Members and Roles

Invite your team and grant exactly the access needed.

An organization is a team. Members join by email invite and are scoped to roles and permission flags — you never share a single admin account across a team.

Roles#

RoleDelegated rights
OwnerEverything, including billing, integrations and the danger zone
AdminFull operational control minus the ownership-only actions
MemberDeploys and works on the resources they can see
ViewerRead-only

On top of the role, granular member permissions switch subsystems on or off: operate deployments, manage resources, and manage automation. A member who can ship code to Staging but not to Production is configured in the same screen as someone who should never touch automation.

Invites and changes#

Invite by email (or handle SSO assignment — see SSO), then change roles or remove members at any time. Removal is immediate and is itself recorded in the audit log. Multiple organizations are supported on Pro and Enterprise, with a switcher in the sidebar.