Roles & Permissions
Every teammate has one of three roles. Roles are fixed and simple — there's no complicated permissions matrix to manage. You pick a role when you invite someone, and you can change it later.
The three roles
| Role | What they can do |
|---|---|
| Owner | Full access — including billing and team management. |
| Member | Configure tracking, manage destinations, and view all data (including customer details). No billing access. |
| Read-only | View dashboards only — no settings, no tokens, no ability to export personal data. |
Every organization has exactly one Owner (the person who created it). Owners aren't invited — ownership belongs to the account creator.
What each role can access
| Capability | Owner | Member | Read-only |
|---|---|---|---|
| View dashboards | ✅ | ✅ | ✅ |
| Configure tracking | ✅ | ✅ | — |
| Manage destinations | ✅ | ✅ | — |
| View customer detail & export data | ✅ | ✅ | — |
| Manage team | ✅ | — | — |
| Manage Stripe connection | ✅ | — | — |
| Manage billing | ✅ | — | — |
Choosing a role
- Give Member to marketers and operators who run the product day to day.
- Give Read-only to executives, clients, or anyone who just needs to see the numbers — it's the safest role, since it never exposes settings or personal data.
- Keep Owner to the person responsible for the account and its billing.
Read-only is great for sharing
Because Read-only seats can't see tokens or export personal data, they're perfect for giving a stakeholder or client visibility without any risk. (Read-only seats are available on higher plans — see Billing & Plans.)