Five roles are available, each mapping to a fixed set of permission keys.
The roles
- Owner — full control, including billing and deletion
- Admin — everything except billing and workspace deletion
- Member — add websites, run scans, view results
- Billing only — invoices and payment methods, nothing else
- Read only — view everything, change nothing
How enforcement works
Permissions are checked on the server for every request, not just hidden in the interface. Hiding an option in a dropdown is not a security control.