> For the complete documentation index, see [llms.txt](https://academy.dnanexus.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://academy.dnanexus.com/billing-access-and-orgs/org-membership-settings.md).

# Org Membership Settings

## Overview

Granular Admin Roles allow Organization Administrators to delegate specific administrative tasks to organization members without granting them full org-wide admin privileges. This enables members to perform targeted, cross-project operations based on their specific responsibilities.

## How to Assign and Manage Roles

Organization admins can manage these roles via self-service across all regions.

* Assigning Roles: You can assign or revoke specific entitlements when inviting a new member to the organization or when editing an existing member's access settings.
* Visibility: All delegated actions and assigned roles can be viewed directly in the organization members list view.

## Accessing Org Membership

1. To access your org’s membership information, select the org in the “Orgs” tab in the top heading on the platform.&#x20;

<figure><img src="/files/NDkdU4lvjcAzViOAnOTT" alt=""><figcaption></figcaption></figure>

2. If you want to change the access of an existing member of an org, check the box on the left hand side of their name, and select “Edit Access”, then select the permissions you are wanting to edit. *Note: if you are wanting to edit the org membership, you will need org admin access to do so.*&#x20;

<figure><img src="/files/mlVYAdG2JBxx77TbYvAF" alt=""><figcaption></figcaption></figure>

3. Select the membership options that apply to the member. You can select if you are going to allow billable activity access (Allowed or Not Allowed), shared project access (Viewer, Uploader, Contributor, or Admin) , and shared apps access (Allowed or Not Allowed).  If they are a member (and not an admin), you can select the options that they can edit in the org, such as Project Member Demotion, Archival Management, Data Search, and Data Deletion. These are described in more detail in the section below titled “Available Roles and Capabilities).  If you select for the member to be an admin, all of the options are “Allowed” or set to “Admin”.&#x20;

<img src="/files/1BPSmxrx03rAPmfV8FmI" alt="" height="581" width="463">

4. If you are adding a new member or org admin, select  “Invite New Member” in the top right heading. *Note: if you are wanting to edit the org membership, you will need org admin access to do so.*

<figure><img src="/files/Rx2QHFKhzd6SX2wXSNRV" alt=""><figcaption></figcaption></figure>

5. Type in the user id or email and select the membership options that apply to the member.  Select the membership options that apply to the new member. You can select if you are going to allow billable activity access (Allowed or Not Allowed), shared project access (Viewer, Uploader, Contributor, or Admin) , and shared apps access (Allowed or Not Allowed).  If they are a member (and not an admin), you can select the options that they can edit in the org, such as Project Member Demotion, Archival Management, Data Search, and Data Deletion. These are described in more detail in the section below titled “Available Roles and Capabilities).  If you select for the member to be an admin, all of the options are “Allowed” or set to “Admin”.&#x20;

<figure><img src="/files/JfMdnYL8Md3lPpGFLM57" alt=""><figcaption></figcaption></figure>

<br>

## Available Roles and Capabilities

Each granular role unlocks specific operations that can be performed across the organization, even if the user is not a member of the specific projects involved:

### 1. Archival Management (archivalManagement)

* What it does: Allows a member to archive and unarchive data objects across all projects in the organization.
* How to use it: A member with this role can execute archive commands using the allCopies option.
* *Note: your org needs a separate license for this feature. Contact the DNAnexus Sales Team ( <sales@dnanexus.com>) for more information.*&#x20;

### 2. Project Member Demotion (projectMemberDemotion)

* What it does: Permits a member to decrease user access levels and audit project access across the organization.
* How to use it: Members can use /org-xxxx/findProjects to list all projects a specific user is in. They can also use /project-xxxx/decreasePermissions to demote a user within a project, without needing to be a member of that project themselves.

### 3. Data Search (dataSearch)

* What it does: Enables a member to search for data objects across all projects in the organization.
* How to use it: Members can use /class-xxxx/listProjects with the allCopiesForOrg parameter. This allows them to list all projects that a specific file copy resides in, even if they are not a member of those projects.

### 4. Data Deletion (dataDeletion)

* What it does: Allows a member to delete data objects across all projects in the organization.
* How to use it: Members can execute /class-xxxx/removeObjects using the overrideProjectAccess parameter to remove a file from any project without being a member of that project.

## Important Limitations and Caveats

When utilizing Granular Admin Roles, please note the following system rules:

* Granting Access: Only full organization admins have the authority to grant these entitlements. A member who holds a granular entitlement cannot grant that same role to other members.
* License Requirements: The archivalManagement role requires the organization to have an active archival license. The other three roles are available to all organizations by default.
* Restricted Data: These granular roles have no impact on data access for UKB/OFH Restricted Projects.
