Team roles and permissions
See what each built-in role (Owner, Admin, Editor, Analyst, Viewer, Billing) can do, how custom roles work on Business, and how API tokens narrow access.
Access is built from permissions. A role is a set of permissions, and every API operation and MCP tool declares the one permission it needs.
Permission matrix#
This table is generated from the code that enforces it.
| Permission | Allows | Owner | Admin | Editor | Analyst | Viewer | Billing |
|---|---|---|---|---|---|---|---|
analytics.read |
View dashboards, stats, live data and reports | ✓ | ✓ | ✓ | ✓ | ✓ | - |
analytics.export |
Create exports and download data | ✓ | ✓ | ✓ | ✓ | - | - |
content.write |
Manage goals, funnels, segments, notes, alerts, email reports, links and dashboards | ✓ | ✓ | ✓ | ✓ | - | - |
sites.manage |
Create sites and change site settings, tracking, privacy, traffic rules, integrations and sharing | ✓ | ✓ | ✓ | - | - | - |
uptime.manage |
Manage uptime checks and status pages | ✓ | ✓ | ✓ | - | - | - |
members.manage |
Invite members and change roles and site access | ✓ | ✓ | - | - | - | - |
tokens.manage |
Create and revoke API tokens for anyone in the workspace (members can always manage their own) | ✓ | ✓ | - | - | - | - |
billing.manage |
Change plan, payment details and view invoices | ✓ | ✓ | - | - | - | ✓ |
workspace.manage |
Workspace settings, security, SSO, webhooks, white label, audit log and deletion | ✓ | ✓ | - | - | - | - |
A member with no access to a site can't see it anywhere, including in lists, exports and the API.
Built-in roles#
- Owner: everything. Every workspace has at least one owner.
- Admin: everything an owner can do.
- Editor: analytics, exports, content (goals, funnels, segments, notes, alerts, reports, links), site settings and uptime. No members, billing, tokens for others or workspace settings.
- Analyst: analytics, exports and content. No site settings.
- Viewer: read-only analytics.
- Billing: plan, payment details and invoices only.
On the Free plan, the Owner, Admin and Viewer roles are available.
Custom roles#
On Business, create roles with any combination of permissions in Workspace settings → Roles (a permission matrix editor), then assign them like built-in roles.
API tokens narrow, never widen#
An API token belongs to a member. Its effective access is:
- permissions = the member's role ∩ the permissions chosen for the token,
- sites = the member's sites ∩ the sites chosen for the token.
If the member's role or site access shrinks, their tokens shrink with it.
Members can always manage their own tokens, and tokens.manage lets admins
manage everyone's.