Roles & Permissions
Every teammate has one of three roles. Roles are fixed and simple — there's no complicated permissions matrix to manage. You pick a role when you invite someone, and you can change it later.
The three roles
| Role | What they can do |
|---|---|
| Owner | Full access — including billing and team management. |
| Member | Configure tracking, manage destinations, and view all data (including customer details). No billing access. |
| Read-only | View dashboards only — no settings, no tokens, no ability to export personal data. |
Every workspace must have at least one Owner, and it starts with the person who created it. You can't invite someone straight in as an Owner, but you can promote an existing member to Owner from Settings → Team & roles — which is how you hand over or share ownership. The last Owner can't be demoted or removed until someone else has been promoted.
What each role can access
| Capability | Owner | Member | Read-only |
|---|---|---|---|
| View dashboards | ✅ | ✅ | ✅ |
| Configure tracking | ✅ | ✅ | — |
| Manage destinations | ✅ | ✅ | — |
| View customer detail & export data | ✅ | ✅ | — |
| Manage team | ✅ | — | — |
| Manage Stripe connection | ✅ | — | — |
| Manage billing | ✅ | — | — |
Choosing a role
- Give Member to marketers and operators who run the product day to day.
- Give Read-only to executives, clients, or anyone who just needs to see the numbers — it's the safest role, since it never exposes settings or personal data.
- Keep Owner to the person responsible for the account and its billing.
Because Read-only seats can't see tokens or export personal data, they're perfect for giving a stakeholder or client visibility without any risk. Every role is available on every plan, including Free — a Read-only teammate simply uses one of your seats like anyone else.