Roles
Seven roles: one Owner, then Admin, Developer, Billing, Viewer, Site Admin, and Site Developer.
A company has exactly one Owner. Everyone else has one of the other six roles. The dashboard asks the API what you can do and hides the rest, so a button you cannot see is one the API would refuse.
The roles
| Role | What it can do |
|---|---|
| Owner | Everything, plus transfer ownership, SSO, and close the company. |
| Admin | Everything except ownership, SSO, and closing the company. |
| Developer | See the team, manage their own API keys, see activity. |
| Billing | See company details. Billing screens arrive later, because plans cannot be bought yet. |
| Viewer | Read-only access to what exists. |
| Site Admin | Full control of the sites they are added to, including SSH, credentials, and who else can use each site. |
| Site Developer | Code, files, the database, and cron on the sites they are added to. Cannot reveal credentials, manage SSH, or invite people. |
Site roles are scoped to sites. A Site Admin or Site Developer sees only the sites they are added to and nothing else in the company. Add them from a site's User management tab. See Give someone access to one site.
Who can invite
The Owner and Admins. See Invitations.
Who can manage SSO
The Owner only. See SSO.
Who can create API keys
Owner, Admin, and Developer, for keys they are allowed to create. The restricted scopes danger:destroy and domains:transfer_out need an expiry on the key. See API keys and scopes.
Change a role
Open Team and change the role from the member row. You cannot change the Owner this way: use transfer ownership.
Quick answers
Can a company have two Owners? No. Exactly one. Transfer ownership to hand it to an Admin.
Can a Site Admin see my other sites? No. Site roles see only the sites they are added to.
Why is a button missing for me? Your role cannot do it. The dashboard hides what the API will refuse.
API
GET /v1/companies/me/membersPATCH /v1/members/{id}GET /v1/sites/{id}/membersPATCH /v1/sites/{id}/members/{member_id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.