Skip to content

Roles and permissions

Every user belongs to one organization and has one of three roles: owner, admin, or member. Permissions are enforced on the server (Laravel policies), not only in the UI.

There is one owner per organization. Collaboration (inviting members) is a Team-plan capability; maintenance features are not gated by role beyond what this page describes. See Plans.

Action Owner Admin Member
View sites, jobs, events, inventory Yes Yes Yes
Add / reconnect / revoke sites Yes Yes No
Delete a site Yes No No
Run backups, restores, updates Yes Yes No
Cancel or retry jobs Yes Yes No
View and manage storage destinations Yes Yes No
Delete a storage destination Yes No No
Connect hosting accounts Yes Yes No
Organization name and members Yes Yes (invite/manage members) No
Change another user’s role Yes No No
Remove a member Yes No No
Billing Yes No No
Security logs Yes No No
View raw site / storage credentials Yes No No

Members cannot change their own role or remove themselves. Nobody can delete the owner.

Owners must enable TOTP 2FA. Admins and members can enable it. Owners cannot turn their 2FA off.

The data model includes teams inside an organization. Day-to-day access today is organization role (owner / admin / member), not a separate per-team permission matrix in the UI.

The product spec also names API scopes such as backup:run, update:run, inventory:read, and events:read. The dashboard uses the table above. When the public API is documented, those scopes will apply to tokens — they are not extra UI roles.