Team Roles and Access
Least privilege by default
Invite colleagues with Admin, Manager, or Viewer roles so people see only the organisations and sites they need. Onboard delivery leads or read-only stakeholders without sharing one master login. Roles pair with separate workspaces so bigger portfolios stay manageable as the team grows.
Why it matters
Safer onboarding, clearer accountability, fewer permission incidents.
Each organisation stays separate
People only see the sites and data for the workspaces they belong to.
Delivery vs read-only
Managers ship; viewers audit or observe dashboards and reports.
Grows with the team
Add seats without restructuring folders or sharing super-admin passwords.
What each role is for
-
Admin: billing, members, destructive actions where allowed.
-
Manager: day-to-day work on sites and settings, within limits admins set.
-
Viewer: read dashboards, exports, and alerts without changing configuration.
Capability matrix
These role permissions are the same on every plan.
| Capability | Admin | Manager | Viewer |
|---|---|---|---|
| Sites & pages | Yes | Yes | View |
| Budgets & schedules | Yes | Yes | View |
| Team invites | Yes | Policy-dependent | No |
Inviting the right people
If you connect automation, use API access and quota visibility for keys and usage. You still choose who gets API access and who may change live monitoring.