Team & roles
This guide covers inviting teammates and managing their access on Settings → Team. Seat limits per plan are in Plans, quotas & entitlements; the plan ladder itself is in Plans & pricing.
The role ladder
Five roles, least to most privileged:
| Role | What it can do |
|---|---|
| Viewer | View links and basic analytics only |
| Analyst | View links, domains, and analytics; no write access |
| Developer | Create and edit links and domains; manage API keys |
| Admin | Full access except billing; can manage team members |
| Owner | Everything, including billing and role changes |
Every org has exactly one owner, and ownership transfer doesn't exist yet: nobody can change the owner's role, remove the owner, or give the role away. These same descriptions appear in the portal under the invite form's Role select.
Open the tab
Go to Settings → Team, or open /settings?tab=team directly. Every member can read the tab. The invite form and pending-invitations list appear for admins and up; role dropdowns appear only for the owner.
Read the member table
One row per member: name, email, role, and join date. Rows sort by join date, oldest first, so the founding owner stays on top. The owner's row shows a solid Owner badge instead of a dropdown or a remove button.
If the list fails to load, the card shows an error banner with a Retry button.
Invite a teammate
- In Invite a teammate, type the person's email and pick a role. The role defaults to Developer, and a one-line hint under the select describes the selected role.
- Click Invite. An "Invitation sent" toast confirms it, the person appears in the Pending invitations list, and the invite email goes out.
- When they accept from the email, they appear in the member table with the role you picked.
You can assign Admin, Developer, Analyst, or Viewer. Owner is never offered: an org has exactly one.
Problems you can hit at this step:
| What happens | Why |
|---|---|
| Inline "Email is required" under the field | The email box is empty; fix it and submit again |
| Toast "An invitation is already pending for this email" | That person has an unaccepted invitation; revoke it first if you want to restart |
| "Team limit reached" banner | Every seat is taken; the email you typed is preserved |
The "Team limit reached" banner reads "You've reached your team member limit. Upgrade your plan to invite more teammates." and its Upgrade button opens the Billing tab.
Pending invitations
The Pending invitations list sits between the invite form and the member table. Each row shows the email, the role badge, the invited date, and a trash button.
- Revoke opens a dialog:
Revoke the invitation to {email}? They won't be able to join the team, and the reserved seat is freed.Confirm and an "Invitation revoked" toast follows. - A revoked invitation frees its seat immediately; the person can be invited again.
- There is no resend. If the email went astray, revoke and invite again.
- At zero pending, the whole section disappears.
- Home's Needs attention strip counts pending invitations too, with a link here: Notifications & alerts.
Change a role
Role changes are owner-only. On any row except your own and the owner's, open the Role dropdown and pick the new role. It applies immediately: a toast names the change ({Name} is now Analyst), and the row updates in place. To undo, pick the previous role the same way.
Remove a member
Admins and owners can remove members.
- Click the trash button on the member's row. It's labeled for screen readers (
Remove {name}) and is deliberately absent on your own row and on the owner's row. - The confirm dialog reads:
Are you sure you want to remove {name} from the team? They will lose access immediately. - Confirm. A "Member removed" toast confirms it and the row disappears.
The owner cannot be removed, by anyone. If a request to remove them is somehow sent anyway, the API answers "The organization owner cannot be removed; transfer ownership first" — ownership transfer is a future feature, so for now the rule is simply that the owner stays.
Seats and the free-plan gate
A seat is held by every member plus every pending invitation. Inviting past the plan's seat limit fails with the "Team limit reached" banner; revoking a pending invitation or removing a member frees the seat immediately.
Starter orgs can't invite at all: the free plan has a single seat, held by the owner. Admins and up see a prompt instead of the invite form: "Team invites available on paid plans", with an Upgrade to unlock button that opens the plans page. Members below admin see only the member table.
Who can do what
| Action | Viewer | Analyst | Developer | Admin | Owner |
|---|---|---|---|---|---|
| View the member list | ✓ | ✓ | ✓ | ✓ | ✓ |
| Invite and revoke invitations | — | — | — | ✓ | ✓ |
| Change roles | — | — | — | — | ✓ |
| Remove members | — | — | — | ✓ | ✓ |
The API enforces the same limits, so a role below the minimum gets a 403 even on a hand-built request.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| "Team limit reached" banner | All seats taken (pending invitations count) | Revoke an unused invitation, remove a member, or upgrade |
| "An invitation is already pending for this email" | An earlier invite isn't accepted yet | Wait for acceptance, or revoke the invitation and invite again |
| "You don't have permission to invite teammates" | Your role is below Admin | Ask an admin or the owner |
| "Failed to update role" toast | Role changes are owner-only | Ask the owner |
| "You don't have permission to remove teammates" | Your role is below Admin | Ask an admin or the owner |
| Error banner instead of the member list | The fetch failed | Click Retry |
| No invite form, only the member table | Your role is below Admin, or the org is on Starter | See the two sections above |