Team roles and permissions
A Team member has one active role. Assign the least access required for the person’s work.
| Capability | Owner | Admin | Developer | Billing |
|---|---|---|---|---|
| View active Team members | Yes | Yes | Yes | Yes |
| Operate Apps and deploys | Yes | Yes | Yes | No |
| View customer App configuration | Yes | Yes | Yes | No |
| View App request-tracing state | Yes | Yes | Yes | Yes |
| Enable or disable App request tracing | Yes | Yes | Yes | No |
| View SSH access settings | Yes | Yes | Yes | Yes |
| Change App configuration, resources, and access | Yes | Yes | No | No |
| Manage any SSH user, grant, and IP range | Yes | Yes | No | No |
| Manage SSH users and keys you created | Yes | Yes | Yes | No |
| Invite, remove, and change member roles | Yes | Yes | No | No |
| Enable MCP access for non-owner People | Yes | Yes | No | No |
| Change the owner’s MCP access | Yes | No | No | No |
| Use App-scoped MCP Diagnostics and Control | Yes | Yes | Yes | No |
| Use Team-level MCP permissions | Yes | Yes | No | Billing read only |
| View and revoke own human MCP connections | Yes | Yes | Yes | Yes |
| Manage all connections and machine credentials | Yes | Yes | No | No |
| View and filter Team activity | Yes | Yes | No | No |
| Manage App email and view delivery records | Yes | Yes | No | No |
| Manage billing and request eligible refunds | Yes | Yes | No | Yes |
| Rename the Team and change its avatar | Yes | Yes | No | No |
| Archive the Team | Yes | No | No | No |
| Transfer Team ownership | Yes | No | No | No |
Each active Team has one owner. The owner has full customer authority for membership, billing, Apps, Team lifecycle, and ownership transfer.
The owner can’t be removed or demoted through normal member management. Transfer ownership to an active admin first. After the recipient accepts, the previous owner becomes an admin.
Admins can manage members and operate Apps. They can change supported App and Team settings and manage billing, but can’t archive the Team or transfer its ownership.
Developer
Section titled “Developer”Developers can operate Apps and deploy code. They can view the customer App configuration needed for their work and can change the App’s request-tracing setting from Diagnostics. They can’t change other protected Team, billing, membership, resource, secret, or access settings. The other narrow exception is SSH: developers can create SSH users and manage users they created, including those users’ keys. They can’t change the App-wide IP allowlist or grant file transfer or database access.
When a developer’s MCP access is enabled, they can authorize Diagnostics or Control for selected Apps. They can’t authorize Team-level MCP permissions.
See Manage SSH access for the complete permission and revocation rules.
Billing
Section titled “Billing”Billing members can manage payment and invoice workflows and review SSH access and request-tracing state without receiving App-operation, tracing-change, SSH-change, or member-management authority.
When a billing member’s MCP access is enabled, they can authorize only
Diagnostics billing.read. Control and App permissions are unavailable.
Some individual actions apply an additional security check or require recent authentication. The portal hides or disables actions that the current role can’t perform. In Team Activity, App labels are resolved only from Apps owned by the selected Team; true Team-level events have no App label.