Team and roles
People get access to your organization by invitation. What they can do once inside is decided by their role, and what they can see is bounded by the workspaces they can reach.
The built-in roles
Three roles exist out of the box.
| Role | For |
|---|---|
| Admin | Full access, including settings, billing configuration and managing other people |
| Member | Day-to-day work: reading customers, subscriptions and invoices without changing how the platform is configured |
| No access | An account that exists but can do nothing. Useful for suspending somebody without deleting them |
A role is a bundle of permissions. The dashboard lists exactly which permissions each role grants, and it is generated from the same source the API enforces, so it is the reference to trust. We deliberately do not mirror that list here: a copy would drift, and a wrong permission table is worse than none.
Roles are organization-wide
A role is not per workspace. Someone who is an admin is an admin everywhere in your organization, including sandbox.
What is bounded per workspace is the data: two permissions govern workspaces, one to see them and one to create, rename or delete them. Somebody without the first sees only the workspace they are in.
Sandbox is not a safety boundary for people
Because roles are organization-wide, giving somebody access so they can "just try things in sandbox" gives them the same role in live. If that is not what you want, the answer is a narrower role, not a different workspace.
People and machines
A role is for a person. An API key is for a system, carries its own scopes, and should be narrower than any human role you would grant.
Do not share a person's credentials with a service. When somebody leaves you disable their account; you should not also have to work out which integrations stop.
Reference
| Topic | When you need it |
|---|---|
| API keys | Access for systems rather than people |
| Workspaces | The boundary a role operates within |
| Security | Two-factor and session policy |
| Organization settings | Where members and invitations live |