Docs

Team & invites

Invite people to your organization, assign roles, and grant per-site access.

Roles

RoleWhat they can do
OWNERFull access including billing, deleting the org, and managing SSO.
ADMINEverything except billing/deletion. Can approve DSAR erasure requests.
EDITORCreate and publish purposes, policies, webhooks. Cannot delete sites or manage keys.
VIEWERRead-only across the console.
DPORead-only plus DSAR approval rights. Use this for your Data Protection Officer.

Inviting someone

  1. Go to TeamInvite member.
  2. Enter the email address and choose a role.
  3. The invitee receives an email with an accept link (valid 7 days). Until they accept, the invite appears as Pending and can be revoked.
Invites are scoped to the organization. The person signs in with Google and lands as a member with the role you chose.

Per-site role grants

If a member's org role is VIEWER but they need EDITOR access on one specific site, grant it in Sites & API keys → [site] → Access. A per-site grant only elevates — it never reduces an org-level role.

Audit log

Every console action (publish, key rotation, DSAR approval, invite, role change) is appended to the org Audit log (read-only, ADMIN/OWNER only). The log is also available via GET /admin/organizations/:id/audit-log (sk_).