Skip to content

Roles

Seven roles: one Owner, then Admin, Developer, Billing, Viewer, Site Admin, and Site Developer.

A company has exactly one Owner. Everyone else has one of the other six roles. The dashboard asks the API what you can do and hides the rest, so a button you cannot see is one the API would refuse.

The roles

Role What it can do
Owner Everything, plus transfer ownership, SSO, and close the company.
Admin Everything except ownership, SSO, and closing the company.
Developer See the team, manage their own API keys, see activity.
Billing See company details. Billing screens arrive later, because plans cannot be bought yet.
Viewer Read-only access to what exists.
Site Admin Full control of the sites they are added to, including SSH, credentials, and who else can use each site.
Site Developer Code, files, the database, and cron on the sites they are added to. Cannot reveal credentials, manage SSH, or invite people.

Site roles are scoped to sites. A Site Admin or Site Developer sees only the sites they are added to and nothing else in the company. Add them from a site's User management tab. See Give someone access to one site.

Who can invite

The Owner and Admins. See Invitations.

Who can manage SSO

The Owner only. See SSO.

Who can create API keys

Owner, Admin, and Developer, for keys they are allowed to create. The restricted scopes danger:destroy and domains:transfer_out need an expiry on the key. See API keys and scopes.

Change a role

Open Team and change the role from the member row. You cannot change the Owner this way: use transfer ownership.

Quick answers

Can a company have two Owners? No. Exactly one. Transfer ownership to hand it to an Admin.

Can a Site Admin see my other sites? No. Site roles see only the sites they are added to.

Why is a button missing for me? Your role cannot do it. The dashboard hides what the API will refuse.

API

  • GET /v1/companies/me/members
  • PATCH /v1/members/{id}
  • GET /v1/sites/{id}/members
  • PATCH /v1/sites/{id}/members/{member_id}

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.