Team and permissions
The Team section manages your organization's members and what each of them can do on each site. It has two tabs: Members & Permissions and Invite Members.
Roles#
| Role | Scope |
|---|---|
| Owner | Full access to every site in the organization. Per-site permissions cannot be restricted for them. |
| Admin | Full access to every site. Can manage members and permissions. |
| Member | Access only to the sites explicitly granted, at the level assigned on each one. |
Owners and admins have full access to every site by definition; the dashboard states that on their card instead of showing a per-site permission list.
Per-site permissions#
For a member, each site can be granted at one of two levels:
On each member's card, Grant access adds a site and Revoke access removes one. The Access to all sites option grants the whole set at once.
A member with no site granted will see No site access when opening AIO. It is not an application error: access has to be granted from here.
Inviting members#
The Invite Members tab adds people to the organization. New members join with the role you assign and — if they are members — with no site access until it is granted.
In local-auth dev mode, member invitations are unavailable and users are provisioned through the repository's seed script.
Good practice#
- Grant Read by default and raise to Read & Write only for people who will launch optimizations or tests: those are the actions that spend balance.
- Keep the number of admins small. Full access to every site includes the integration's danger zone.
- Review permissions when someone changes responsibilities; access changes are recorded in Change history.
Switching organization#
The switcher in the top bar moves between organizations, manages them or creates a new one. Each organization has its own sites, its own plan and its own balance.