Skip to content

Teams and roles

An organization can have several members – the number depends on the plan, and pending invitations count toward the limit too. Owners and admins invite people in Team → Invite a colleague: enter the email, choose a role and click Send invite. The invitee gets an email with a link that is valid for 7 days, signs up or signs in with that same (verified) email address, and joins with the chosen role. Inviting the same address again replaces the previous invitation; pending invitations can be revoked in Pending invitations.

Invitation emails come from Frontmail, so they’re limited to prevent abuse: an address can get at most 3 invitations per day (from all organizations together) and an organization can send at most 50 per day. Organization names can’t contain links, and names in invitation emails are shown as plain text (links and phone numbers are removed).

One person can belong to several organizations and switch between them in the top bar.

Role Intended for
Owner The account holder. Exactly one per organization; full access including billing, deleting the organization and transferring ownership.
Admin Team leads – everything except changing billing, deleting the organization and transferring ownership.
Developer Builds and maintains services and templates, works with messages and statistics. No security settings, team or billing management.
Viewer Read-only access to templates, history and statistics, e.g. support staff checking History.
Billing Accounting – plan, credits, invoices and billing details, plus read-only access to the rest of the organization.
Permission Owner Admin Developer Viewer Billing
View overview, statistics, history (incl. message content), templates, services, contacts, suppressions and the team list ✓ ✓ ✓ ✓ ✓
Create / edit / delete services and templates, test sends ✓ ✓ ✓ – –
Resend messages, release / discard held messages ✓ ✓ ✓ – –
Delete contacts, export contacts, add / remove suppressions ✓ ✓ ✓ – –
View keys and security settings ✓ ✓ ✓ – –
Create / revoke private keys, rotate the public key, change security settings (allowed websites, bot protection, block list, rate limit, hold/reject mode) ✓ ✓ – – –
Invite / remove members, change roles, organization settings (name, time zone, language) ✓ ✓ – – –
Audit log ✓ ✓ – – –
View billing (plan, credits, invoices) ✓ ✓ – – ✓
Change plan, buy packs, auto top-up, billing details, customer portal ✓ – – – ✓
Delete organization, transfer ownership ✓ – – – –

Rules for changing roles:

  • Only the owner can invite, promote, demote or remove admins and billing members. Everyone else can only hand out roles whose permissions they have themselves – so an admin manages developers and viewers, but can’t give anyone (for example a second account of their own) the right to change the plan or payment details.
  • Nobody can assign the owner role – use Transfer ownership instead.
  • Nobody can change their own role.
  • The owner can’t be removed; transfer ownership first.

The owner can hand the organization over in Team → Transfer ownership: pick a member and confirm. The new owner gets full control and the previous owner becomes an admin.

Removing a member revokes their access to the organization immediately. Keys belong to the organization, not to the person, so they keep working – revoke them separately if needed. Every member except the owner can also Leave the organization themselves.

On a downgrade to a plan with fewer users, the extra members are frozen rather than removed (the owner and the longest-standing members stay active). A frozen member can still sign in but acts as a viewer, and doesn’t receive organization emails, until you upgrade again (see Plan changes).