Docs
Team & invites
Invite people to your organization, assign roles, and grant per-site access.
Roles
| Role | What they can do |
|---|---|
| OWNER | Full access including billing, deleting the org, and managing SSO. |
| ADMIN | Everything except billing/deletion. Can approve DSAR erasure requests. |
| EDITOR | Create and publish purposes, policies, webhooks. Cannot delete sites or manage keys. |
| VIEWER | Read-only across the console. |
| DPO | Read-only plus DSAR approval rights. Use this for your Data Protection Officer. |
Inviting someone
- Go to Team → Invite member.
- Enter the email address and choose a role.
- The invitee receives an email with an accept link (valid 7 days). Until they accept, the invite appears as Pending and can be revoked.
Invites are scoped to the organization. The person signs in with Google and lands as a member with the role you chose.
Per-site role grants
If a member's org role is VIEWER but they need EDITOR access on one specific site, grant it in Sites & API keys → [site] → Access. A per-site grant only elevates — it never reduces an org-level role.
Audit log
Every console action (publish, key rotation, DSAR approval, invite, role change) is appended to the org Audit log (read-only, ADMIN/OWNER only). The log is also available via GET /admin/organizations/:id/audit-log (sk_).