Skip to content
Reference

Team roles and permissions

A Team member has one active role. Assign the least access required for the person’s work.

CapabilityOwnerAdminDeveloperBilling
View active Team membersYesYesYesYes
Operate Apps and deploysYesYesYesNo
View customer App configurationYesYesYesNo
View App request-tracing stateYesYesYesYes
Enable or disable App request tracingYesYesYesNo
View SSH access settingsYesYesYesYes
Change App configuration, resources, and accessYesYesNoNo
Manage any SSH user, grant, and IP rangeYesYesNoNo
Manage SSH users and keys you createdYesYesYesNo
Invite, remove, and change member rolesYesYesNoNo
Enable MCP access for non-owner PeopleYesYesNoNo
Change the owner’s MCP accessYesNoNoNo
Use App-scoped MCP Diagnostics and ControlYesYesYesNo
Use Team-level MCP permissionsYesYesNoBilling read only
View and revoke own human MCP connectionsYesYesYesYes
Manage all connections and machine credentialsYesYesNoNo
View and filter Team activityYesYesNoNo
Manage App email and view delivery recordsYesYesNoNo
Manage billing and request eligible refundsYesYesNoYes
Rename the Team and change its avatarYesYesNoNo
Archive the TeamYesNoNoNo
Transfer Team ownershipYesNoNoNo

Each active Team has one owner. The owner has full customer authority for membership, billing, Apps, Team lifecycle, and ownership transfer.

The owner can’t be removed or demoted through normal member management. Transfer ownership to an active admin first. After the recipient accepts, the previous owner becomes an admin.

Admins can manage members and operate Apps. They can change supported App and Team settings and manage billing, but can’t archive the Team or transfer its ownership.

Developers can operate Apps and deploy code. They can view the customer App configuration needed for their work and can change the App’s request-tracing setting from Diagnostics. They can’t change other protected Team, billing, membership, resource, secret, or access settings. The other narrow exception is SSH: developers can create SSH users and manage users they created, including those users’ keys. They can’t change the App-wide IP allowlist or grant file transfer or database access.

When a developer’s MCP access is enabled, they can authorize Diagnostics or Control for selected Apps. They can’t authorize Team-level MCP permissions.

See Manage SSH access for the complete permission and revocation rules.

Billing members can manage payment and invoice workflows and review SSH access and request-tracing state without receiving App-operation, tracing-change, SSH-change, or member-management authority.

When a billing member’s MCP access is enabled, they can authorize only Diagnostics billing.read. Control and App permissions are unavailable.

Some individual actions apply an additional security check or require recent authentication. The portal hides or disables actions that the current role can’t perform. In Team Activity, App labels are resolved only from Apps owned by the selected Team; true Team-level events have no App label.