Roles and permissions
Every user belongs to one organization and has one of three roles: owner, admin, or member. Permissions are enforced on the server (Laravel policies), not only in the UI.
There is one owner per organization. Collaboration (inviting members) is a Team-plan capability; maintenance features are not gated by role beyond what this page describes. See Plans.
Role summary
Section titled “Role summary”| Action | Owner | Admin | Member |
|---|---|---|---|
| View sites, jobs, events, inventory | Yes | Yes | Yes |
| Add / reconnect / revoke sites | Yes | Yes | No |
| Delete a site | Yes | No | No |
| Run backups, restores, updates | Yes | Yes | No |
| Cancel or retry jobs | Yes | Yes | No |
| View and manage storage destinations | Yes | Yes | No |
| Delete a storage destination | Yes | No | No |
| Connect hosting accounts | Yes | Yes | No |
| Organization name and members | Yes | Yes (invite/manage members) | No |
| Change another user’s role | Yes | No | No |
| Remove a member | Yes | No | No |
| Billing | Yes | No | No |
| Security logs | Yes | No | No |
| View raw site / storage credentials | Yes | No | No |
Members cannot change their own role or remove themselves. Nobody can delete the owner.
Two-factor authentication
Section titled “Two-factor authentication”Owners must enable TOTP 2FA. Admins and members can enable it. Owners cannot turn their 2FA off.
The data model includes teams inside an organization. Day-to-day access today is organization role (owner / admin / member), not a separate per-team permission matrix in the UI.
API-oriented scopes (for later)
Section titled “API-oriented scopes (for later)”The product spec also names API scopes such as backup:run, update:run, inventory:read, and events:read. The dashboard uses the table above. When the public API is documented, those scopes will apply to tokens — they are not extra UI roles.