Roles
Inviting team members and managing their access.
A workspace can have more than one member. Invite teammates by email from Workspace Settings → Members, and assign each one a role.
Roles
Roles are ordered by privilege, each including everything below it:
| Role | Can do |
|---|---|
| Viewer | Read-only access to projects and services. |
| Developer | Create and manage services — serverlets, proxies, DNS, and so on. |
| Billing Manager | Everything a Developer can, plus manage billing and credit. |
| Administrator | Everything above, plus manage workspace settings and members. |
| Owner | Full control, including deleting the workspace. |
Restricting access to specific projects
By default, a member’s role applies across every project in the workspace. If you need someone to only work in one project — a contractor on a single app, for example — you can restrict their access to a specific set of projects when inviting or editing them. Their role still determines what they can do; the restriction only narrows which projects they can do it in. Workspace-level actions like billing and workspace settings aren’t affected by a project restriction.
Removing a member
Removing a member revokes their access immediately. It doesn’t affect anything they created — serverlets, DNS zones, and other services stay in the project.
Last updated