Skip to main content
Every member of an organization holds exactly one of three roles. Roles are per organization — you can be an owner in your own and a member in a client’s.

The three roles

Owner — assigned to whoever creates the organization. Only an owner can change the plan or delete the organization. Owner can be granted to someone else through the role dropdown; what can’t happen is the organization ending up with none, so the last owner can’t be demoted or removed. Admin — full operational control. Manages projects and members, but can’t change billing or delete the organization. Member — the default. Full access to the work itself: view and edit every project, add keywords, run audits, build reports. Can’t manage other members or delete projects.
There is no read-only or per-project role. Every member can edit every project in the organization. If someone needs access to one project but not another, put those projects in separate organizations.

Permissions in full

Projects and data

Organization and members

Billing

Everyone can see how much of the plan’s quota is used — that’s operational information a member needs before starting a big audit. Only the owner can spend money.

Notifications and API keys

Any member can create an API key, and a key acts as an owner — it can delete projects and open the billing portal, neither of which a member can do in the dashboard. Treat key creation as a shared responsibility and review your key list periodically.

Rules that apply to everyone

  • You can’t change your own role from the Team page. Your row shows a static badge rather than a dropdown.
  • You can’t remove yourself there either; another admin has to.
  • The last owner is protected. Demoting or removing them fails, because an organization with no owner can’t be administered at all — not recoverable through the product.
Note the last point is about the last owner, not the owner. With two owners, either can be demoted.

Choosing a role

Default to Member — but note that members can’t create projects, which is the one restriction likely to surprise someone. If a person needs to add sites, they need admin. Everything else a member can’t do is destructive or administrative, and easy to escalate later from the role dropdown on the Team page.