Documentation

Team and roles

Invite people to a site, what owner, admin and viewer can each do, and how billing transfers work.

Roles

Access is per site and comes in three levels. Membership is independent per site, so someone can be an admin on one and a viewer on another.

RoleWhat it can do
OwnerEverything, including deleting the site, managing every member, and the transfer flows. Every site has exactly one owner.
AdminManage settings, keys, sharing, funnels and members: everything except deleting the site or removing its owner.
ViewerRead everything, change nothing. Dashboards, funnels and settings are visible read-only, and the first control they cannot use says so up front.

Invite someone

Send an invite by email

DashboardSiteTeam

Invite from the site's Team tab. Each pending invitation shows its status and expiry beside it, so you can see who has not accepted yet.

Resend if it expired

Resending mints a fresh link and the previous one stops working, so a stale invite can never be used after you send a new one.

Who pays, and handing that over

One member is the billing owner: the site counts against their plan. Two flows change that, both under Settings.

Billing transfer

The billing owner nominates a member, who accepts or declines. If the acceptor's plan has no room, the transfer still completes and the site pauses until they upgrade; the flow says so before anyone commits.

Leaving or being removed

An owner leaving names a successor first, so a site is never left ownerless.

Security

Destructive steps ask for a recent sign-in

Deleting a site, deleting an account and removing a member's access to money all ask for a recent re-authentication, not just a live cookie. Every credential event on an account, a key created, an app connected, a first use from a new source, is journalled and visible to the account owner.

Common questions