Team & roles
Team & roles in the Workspace area (Admin) — route /workspace/team-roles.
Team & roles lives in the Workspace area of the dashboard, under Admin.
At a glance#
| Dashboard route | /workspace/team-roles |
| Area | Workspace (workspace) |
| Group | Admin |
| Platforms | Available for every app platform. |
What it does#
Team & roles manages who is in the workspace and what they can do. You invite by email, pick a role, and the invite produces a join link you can copy and send yourself. Existing members can have their role changed or be removed.
Roles are fixed, and each is a real permission boundary:
| Role | What it grants |
|---|---|
OWNER | Full access — billing, members, and deleting the organisation. |
ADMIN | Manage members, integrations and settings. No billing, no delete. |
DEVELOPER | Connect integrations, file tickets, manage SDK keys. |
TESTER | Triage issues and send test alerts. |
PRODUCT | Read analytics and product data. |
SUPPORT | Read-only, for support workflows. |
VIEWER | Read-only. |
OWNER is not offerable on an invite — it is granted by transferring ownership, not by inviting
someone into it.
When to use it#
At onboarding, at offboarding, and on a review cadence. The offboarding half is the one that gets
skipped: a departed contractor with DEVELOPER still holds SDK key management.
Workflow#
Invite with the least role that works
VIEWERandPRODUCTcover most people who want to look at data.DEVELOPERand above can change things that affect data collection.Send the join link yourself if the invite email is slow
The link is generated on invite and copyable from the list, so you are never blocked on mail delivery.
Revoke invites you did not intend
An outstanding invite is a live credential until it is revoked or accepted.
Review membership periodically
Every membership change is recorded in the audit log, which makes the review a read rather than an investigation.
Permissions and prerequisites#
Managing members requires ADMIN or OWNER. Everyone else sees the list read-only.
Limits and edge cases#
Roles are org-wide. They are not scoped per app or per environment, so
DEVELOPERapplies everywhere in the workspace.You cannot invite an
OWNER. Use ownership transfer.Removing a member is immediate and does not delete anything they created.
Troubleshooting#
An invite was never received. Copy the join link from the list and send it directly. Invite email can be filtered, especially by corporate mail.
Someone cannot see a page they should. Check their role against the table above rather than
assuming a bug — several dashboard areas are gated on ADMIN.
Where the data comes from#
Served by
Admin
Organizations