Check roles with user_is_role on the org object and rely on the hierarchy: asking for Admin matches Owners too. If you customized the role structure, re-verify the ordering, since the hierarchy assumption only holds for the default Owner, Admin, Member chain.

Context: Official docs (propelauth-py README): documents a gotcha that trips agents writing role checks. PropelAuth roles are hierarchical by default: Owner outranks Admin, which outranks Member, and the user_is_role check respects that ordering. Agents that compare role names as strings, or demand an exact Admin match when the caller is an Owner, lock out the most privileged users.