문서
문서 둘러보기

Team roles and permissions

See what each built-in role (Owner, Admin, Editor, Analyst, Viewer, Billing) can do, how custom roles work on Business, and how API tokens narrow access.

Markdown으로 보기

Access is built from permissions. A role is a set of permissions, and every API operation and MCP tool declares the one permission it needs.

Permission matrix#

This table is generated from the code that enforces it.

Permission Allows Owner Admin Editor Analyst Viewer Billing
analytics.read View dashboards, stats, live data and reports ✓ ✓ ✓ ✓ ✓ -
analytics.export Create exports and download data ✓ ✓ ✓ ✓ - -
content.write Manage goals, funnels, segments, notes, alerts, email reports, links and dashboards ✓ ✓ ✓ ✓ - -
sites.manage Create sites and change site settings, tracking, privacy, traffic rules, integrations and sharing ✓ ✓ ✓ - - -
uptime.manage Manage uptime checks and status pages ✓ ✓ ✓ - - -
members.manage Invite members and change roles and site access ✓ ✓ - - - -
tokens.manage Create and revoke API tokens for anyone in the workspace (members can always manage their own) ✓ ✓ - - - -
billing.manage Change plan, payment details and view invoices ✓ ✓ - - - ✓
workspace.manage Workspace settings, security, SSO, webhooks, white label, audit log and deletion ✓ ✓ - - - -

A member with no access to a site can't see it anywhere, including in lists, exports and the API.

Built-in roles#

  • Owner: everything. Every workspace has at least one owner.
  • Admin: everything an owner can do.
  • Editor: analytics, exports, content (goals, funnels, segments, notes, alerts, reports, links), site settings and uptime. No members, billing, tokens for others or workspace settings.
  • Analyst: analytics, exports and content. No site settings.
  • Viewer: read-only analytics.
  • Billing: plan, payment details and invoices only.

On the Free plan, the Owner, Admin and Viewer roles are available.

Custom roles#

On Business, create roles with any combination of permissions in Workspace settings → Roles (a permission matrix editor), then assign them like built-in roles.

API tokens narrow, never widen#

An API token belongs to a member. Its effective access is:

  • permissions = the member's role ∩ the permissions chosen for the token,
  • sites = the member's sites ∩ the sites chosen for the token.

If the member's role or site access shrinks, their tokens shrink with it. Members can always manage their own tokens, and tokens.manage lets admins manage everyone's.