Plan availability | All plan types |
Permissions |
|
Platform(s) | Web/Browser, Mac app, Windows app, and mobile apps |
Admin role types
Action | Super Admin | Org Unit Admin | User Admin | Integration Admin | Brand Admin |
|---|---|---|---|---|---|
Configure SSO and SCIM for the organization | ✅ | ||||
Full visibility over all users and workspaces org-wide | ✅ | ||||
Visibility into specific org units (where assigned) | ✅ | ✅ | |||
Control Airtable licenses | ✅ | ✅ | |||
Create new org units | ✅ | ||||
Grant super admin access to other users | ✅ | ||||
Grant org unit admin access | ✅ | ✅ | |||
Configure domains and authentication settings | ✅ | ||||
Establish organization-wide security policies | ✅ | ||||
Manage rules for APIs and compliance tools (EKM, DLP, audit logs) | ✅ | ||||
Delete workspaces, bases, and interfaces | ✅ | ✅ | |||
Move workspaces between org units | ✅ | ||||
Deactivate user accounts | ✅ | ||||
Sign users out of all sessions | ✅ | ||||
Require users to sign in with SSO | ✅ | ||||
Update user email addresses | ✅ | ||||
Remove users from workspaces, bases, and interfaces | ✅ | ✅ | ✅ | ||
Update user permissions on workspaces, bases, and interfaces | ✅ | ✅ | ✅ | ||
Manage groups and group memberships | ✅ | ✅ | ✅ | ||
Manage integration settings | ✅ | ✅ | |||
Configure HyperDB | ✅ | ✅ | ✅ | ||
Manage organization branding settings | ✅ | ✅ | |||
Manage organizational resources | ✅ | ✅ |
Admin panel page access by role type
Page | Super Admin | Org Unit Admin | User Admin | Integration Admin | Brand Admin |
|---|---|---|---|---|---|
Organization | ✅ | ||||
Users | ✅ | ✅ | ✅ | ||
Roles | ✅ | ✅ | |||
Groups | ✅ | ✅ | ✅ | ||
Solutions | ✅ | ✅ | |||
Workspaces | ✅ | ✅ | ✅ | ||
Bases | ✅ | ✅ | ✅ | ||
Interfaces | ✅ | ✅ | ✅ | ||
Data sets | ✅ | ✅ | |||
HyperDB | ✅ | ✅ | ✅ | ||
Managed apps | ✅ | ✅ | |||
Components | ✅ | ✅ | |||
Reports | ✅ | ✅ | |||
Settings (Security & compliance) | ✅ | ||||
Settings (Integrations & development) | ✅ | ✅ | |||
Settings (Org resources) | ✅ | ✅ |
User types & account categories
User Type | Description | Key Characteristics |
|---|---|---|
Internal Users (Members) | Users whose email domain matches one of the organization's verified domains |
|
External Users | Users with email domains that do not match the organization's verified domains |
|
Guest Users | Users not claimed but with matching enterprise domain |
|
Deactivated Users | Previously active users who have been deactivated by an administrator |
|
Seat types (license types)
Enterprise organizations use seat types to categorize users based on their highest access level. Seat types determine billing and control who can upgrade user permissions.
Seat Type | Billable | Description |
|---|---|---|
Editor | ✅ | User's highest access level causes them to be billable. Can create, edit, and modify content. This includes Owner, Creator, and Editor permissions at the workspace, base, or interface level. |
Portal Editor | ✅ | External users who have access through a portal. Billable category for external collaborators. |
Viewer | User's highest access level does not trigger billing. Read-only access to content. Users with Read-only access permissions can be upgraded by workspace or base owners. | |
Viewer (Restricted) | Can only be upgraded to Editor via an admin user or service account. Provides controlled access with limited upgrade paths. |
Bulk actions by admin type
Note
Enterprise Hub must be enabled to use the actin listed in this section.
Action | Super Admin (Org Level) | Super Admin (Org Unit Level) | Org Unit Admin |
|---|---|---|---|
Sign out of all sessions | ✅ | ✅ | |
Add admin access | ✅ | ✅ | ✅ |
Change seat type | ✅ | ✅ | |
Add to an org unit | ✅ | ✅ | |
Unassign from org unit | ✅ | ✅ | |
Remove access | ✅ | ✅ | ✅ |
Deactivate | ✅ | ✅ |
Bulk actions without enterprise hub enabled
Action | Admin |
|---|---|
Sign out of all sessions | ✅ |
Add admin access | ✅ |
Change seat type | ✅ |
Remove access | ✅ |
Deactivate | ✅ |
Deactivation & access removal
Action | Effect |
|---|---|
Deactivate | User cannot log into Airtable at all. Account is suspended but ownership of bases and workspaces is retained. |
Remove Access | User loses workspace/base privileges but can still log into Airtable and create new workspaces, bases, and interfaces. |
FAQs
Can external users be granted admin access?
No, all admins must be internal collaborators.
How many licenses does a user need when working across an organization?
Users need only 1 license for activity across the entire organization.
Can service accounts be upgraded to super admin access?
Yes. Service accounts can be upgraded to super admin access.