Not available yet. The roles below exist in the database and are enforced today. The screens for assigning them are not built.
Four roles, in order: owner > admin > member > viewer.
Everything a higher role can do, so can every role above it. A role applies across your whole organisation — there is no per-site role.
The complete table
| Owner | Admin | Member | Viewer | |
| Analytics | ||||
| View any site's dashboard | ✅ | ✅ | ✅ | ✅ |
| Use drill-down filters and date ranges | ✅ | ✅ | ✅ | ✅ |
| View the AI panel | ✅ | ✅ | ✅ | ✅ |
| Export data | ✅ | ✅ | ✅ | ✅ |
| Sites | ||||
| Add a site | ✅ | ✅ | ✅ | ❌ |
| Edit a site's settings, exclusions, identity mode | ✅ | ✅ | ✅ | ❌ |
| Delete a site | ✅ | ✅ | ❌ | ❌ |
| Sharing | ||||
| Create a share link | ✅ | ✅ | ✅ | ❌ |
| Revoke a share link | ✅ | ✅ | ✅ | ❌ |
| API keys | ||||
| Create an API key | ✅ | ✅ | ❌ | ❌ |
| Revoke an API key | ✅ | ✅ | ❌ | ❌ |
| Team | ||||
| See who is on the team | ✅ | ✅ | ✅ | ✅ |
| Invite someone | ✅ | ✅ | ❌ | ❌ |
| Change someone's role | ✅ | ✅ | ❌ | ❌ |
| Remove someone | ✅ | ✅ | ❌ | ❌ |
| Billing | ||||
| See the plan and usage | ✅ | ✅ | ❌ | ❌ |
| Change plan, card, invoices | ✅ | ❌ | ❌ | ❌ |
| The organisation | ||||
| Delete the organisation | ✅ | ❌ | ❌ | ❌ |
| Transfer ownership | ✅ | ❌ | ❌ | ❌ |
The distinctions worth knowing
Admin cannot touch billing. That is the whole reason admin exists as a separate role from owner: someone who runs the analytics day to day, including deleting a site and managing keys, without reaching your card. "Can edit" is not an answer to "can they change my subscription", and this row is why.
Member can edit but cannot delete a site. A member can add sites, change settings and manage exclusions. They cannot remove a site and its history. That is the one irreversible action, and it needs admin.
Viewer is genuinely read-only. They can look at everything and change nothing. If that is all someone needs and they do not need to sign in, a share link is better still — it costs no seat.
Everyone sees every site. Roles are organisation-wide. There is no way to give someone access to one site and not another. If you need that, the answer today is a share link scoped to the one site.
Everyone can see who is on the team. Names and roles are visible to every member, including viewers.
Which role to give
| They need to | Role |
| Only look at numbers, and can use a link | No seat — share link |
| Only look at numbers, signed in as themselves | Viewer |
| Run analytics day to day, add sites, manage exclusions | Member |
| All of that, plus delete sites, manage keys and the team | Admin |
| All of that, plus billing | Owner |
Give the lowest role that works. Moving someone up later takes seconds.
The owner
Every organisation has exactly one owner — whoever created it.
Only the owner can change billing and only the owner can delete the organisation. To hand that over, transfer ownership; the previous owner becomes an admin.
You cannot remove the owner. Transfer ownership first, then remove them.