Team and roles
The five roles, what each can do, invitations, and ownership transfer.
The five roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing, member management, ownership transfer, and workspace deletion |
| Admin | Manage members and all product configuration and data; no billing |
| Analyst | Read everything and act on findings — acknowledge incidents, progress actions, export |
| Viewer | Read-only across the product |
| Billing | Billing, invoices, and plan changes, plus read access to the product |
Every workspace must have at least one Owner. The last Owner cannot be removed, demoted, or leave without first transferring ownership to another member.
What each role cannot do
Permissions are enforced on the server for every action. Hiding a button is a convenience, never the control — a Viewer who constructs the request by hand is refused just the same.
- Viewer cannot change sources, competitors, prompts, or settings, cannot progress an action or acknowledge an incident, and cannot export.
- Analyst cannot invite or remove members, change roles, or touch billing.
- Admin cannot see invoices, change the plan, or delete the workspace.
- Billing cannot change clinic configuration or act on findings.
Inviting somebody
Invite by email address and choose the role at the point of invitation. The invitation:
- expires after a fixed period,
- can be revoked or resent at any time before it is accepted,
- can be accepted only once, and only by the address it was sent to,
- is recorded in the audit trail, as are acceptance, revocation, and expiry.
Inviting an address that already has a pending invitation resends rather than creating a second one.
Changing a role
An Owner or Admin can change a member's role from the members list. The change takes effect immediately on the member's next action — it does not wait for them to sign out.
Transferring ownership
An Owner can promote another member to Owner. To hand over completely, promote the new Owner and then demote or remove yourself. There is no state in which a workspace has no Owner.
Removing somebody
Removal revokes their sessions for that workspace immediately. Their name remains on the audit records of actions they took, because an audit trail that can be edited by removing a person is not an audit trail.
Was this page helpful?