Skip to main content
Every member of an organization has one of three roles. They differ only in who can manage the team — none of them restricts what you can do with connections, keys, webhooks or the API.

What that means in practice

Everything an Admin can do, plus the ability to act on other Owners. Owner is not assignable from the Team panel — the role dropdown offers Admin and Member only — so an organization’s owners are set when it is created rather than handed around casually.
Can invite, remove and change the role of Members and other Admins, but cannot touch an Owner. This is the right role for whoever runs the team day to day.
Full use of the product — connect accounts, create API keys, add webhooks, read logs — with the Team panel read-only. This is the right default for engineers.

What no role restricts

There is no read-only role, and no role that can use the API but not connect accounts. Anyone in the organization can:
  • Connect and disconnect social accounts
  • Create and revoke API keys
  • Add, edit and delete webhook endpoints, and rotate their signing secrets
  • Read request logs for their own keys
  • Publish test posts to any connected account
Any member can create an API key that publishes to every connected account in the organization. If you need separation between teams or between clients, use separate organizations rather than roles.

Leaving

You can remove yourself from an organization from the same row, as long as you are not an Owner. An Owner cannot leave.

Invite your team

Sending, resending and cancelling invitations.

Keep keys secure

What to revoke when someone leaves.