Manage members and roles
Invite collaborators with the least privilege they need, review membership regularly, and protect workspace ownership.
Invite a member
- Enter the teammate’s email address.
- Select developer, admin, billing, or viewer.
- Send the invitation. It expires after seven days and appears in Live data until accepted, expired, or revoked.
Choose a role
- Owner
- Ultimate workspace ownership. Keep at least two owners for operational resilience.
- Admin
- Team and operational administration, including invitations and role changes.
- Developer
- Projects, keys, integrations, policies, lockfiles, and managed verification workflows.
- Billing
- Commercial workflows such as subscription, private prices, invoices, and audit exports.
- Viewer
- Read-only inspection plus safe evaluation and lockfile verification workflows.
Permissions are enforced by the API
The UI may display shared workspace data, but every mutation is re-authorized server-side. A rejected action means the current role or plan does not allow it.
Change or remove access
Owners and admins can change roles using the member user ID shown in Live data. Removing a member takes effect immediately. Review keys, endpoints, and notification ownership after offboarding.
Limits and safeguards
- The last workspace owner cannot be removed or demoted.
- Free supports 1 member, Pro 10, and Business 50.
- Pending, unexpired invitations count toward the member limit.
- Use viewer for reviews that do not require configuration changes.