# Team roles and permissions

> See what each built-in role (Owner, Admin, Editor, Analyst, Viewer, Billing) can do, how custom roles work on Business, and how API tokens narrow access.

Access is built from **permissions**. A role is a set of permissions, and
every [API operation](/docs/api) and MCP tool declares the one permission
it needs.

## Permission matrix

This table is generated from the code that enforces it.

| Permission | Allows | Owner | Admin | Editor | Analyst | Viewer | Billing |
|---|---|---|---|---|---|---|---|
| `analytics.read` | View dashboards, stats, live data and reports | ✓ | ✓ | ✓ | ✓ | ✓ | - |
| `analytics.export` | Create exports and download data | ✓ | ✓ | ✓ | ✓ | - | - |
| `content.write` | Manage goals, funnels, segments, notes, alerts, email reports, links and dashboards | ✓ | ✓ | ✓ | ✓ | - | - |
| `sites.manage` | Create sites and change site settings, tracking, privacy, traffic rules, integrations and sharing | ✓ | ✓ | ✓ | - | - | - |
| `uptime.manage` | Manage uptime checks and status pages | ✓ | ✓ | ✓ | - | - | - |
| `members.manage` | Invite members and change roles and site access | ✓ | ✓ | - | - | - | - |
| `tokens.manage` | Create and revoke API tokens for anyone in the workspace (members can always manage their own) | ✓ | ✓ | - | - | - | - |
| `billing.manage` | Change plan, payment details and view invoices | ✓ | ✓ | - | - | - | ✓ |
| `workspace.manage` | Workspace settings, security, SSO, webhooks, white label, audit log and deletion | ✓ | ✓ | - | - | - | - |

A member with no access to a site can't see it anywhere, including in
lists, exports and the API.

## Built-in roles

- **Owner:** everything. Every workspace has at least one owner.
- **Admin:** everything an owner can do.
- **Editor:** analytics, exports, content (goals, funnels, segments, notes,
  alerts, reports, links), site settings and uptime. No members, billing,
  tokens for others or workspace settings.
- **Analyst:** analytics, exports and content. No site settings.
- **Viewer:** read-only analytics.
- **Billing:** plan, payment details and invoices only.

On the Free plan, the Owner, Admin and Viewer roles are available.

## Custom roles

On Business, create roles with any combination of permissions in
**Workspace settings → Roles** (a permission matrix editor), then assign
them like built-in roles.

## API tokens narrow, never widen

An [API token](/docs/api/authentication) belongs to a member. Its effective
access is:

- **permissions** = the member's role ∩ the permissions chosen for the
  token,
- **sites** = the member's sites ∩ the sites chosen for the token.

If the member's role or site access shrinks, their tokens shrink with it.
Members can always manage their own tokens, and `tokens.manage` lets admins
manage everyone's.
