The three layers
Each layer is granted separately, and a role at one layer does not imply a role at another. Account Administrators are the exception: they can access everything on the account.
| Layer | What it covers | Where you grant it | Roles |
|---|---|---|---|
| Account | Account-wide settings, users, teams, API keys and billing | Users and Teams screens | Account Administrator, Billing Administrator |
| Project | One project, and the inboxes, designs and authenticators in it | Project switcher, then the project's settings | Admin, Editor, Viewer |
| Inbox | One inbox, when that inbox is restricted | The inbox's Manage access tab | Admin, Writer, Viewer |
Account roles
You can give a user or team either or both of the account roles. Anyone without one is a standard user.
| Role | What they can do |
|---|---|
| Account Administrator | Manage account-wide settings, users, teams and API keys. Access every project and every inbox, including restricted ones |
| Billing Administrator | Manage your subscription, plan level, billing contacts and invoices |
Project roles
A user or team must be a member of a project to see it. Members of a project can see every inbox in it that is not restricted.
| Role | What they can do |
|---|---|
| Viewer | View the project and everything inside it. In any inbox that is not restricted, the same access as an inbox Writer. Read TOTP codes from authenticator devices |
| Editor | Everything a Viewer can do, plus create and delete inboxes, inbox Admin access to every inbox in the project, and create, edit and delete designs and authenticator devices |
| Admin | Everything an Editor can do, plus rename the project, manage its members, and delete it |
Inbox roles
You grant inbox roles only on an inbox that is restricted. An inbox that is not restricted takes its access from its project instead, and every member of that project already holds an effective role on it:
- A project Viewer has the same access as an inbox Writer.
- A project Editor or Admin has the same access as an inbox Admin, whether the inbox is restricted or not.
Restricting an inbox therefore does not grant access, it withdraws it. The inbox disappears for project Viewers until you give them a role on it directly.
| Role | What they can do |
|---|---|
| Viewer | View messages in the inbox, and open screenshots other people have generated |
| Writer | View messages, send, reply or forward from the inbox, generate screenshots, and manage the inbox's own API keys and rules |
| Admin | Full control, including managing inbox settings and access |
See Manage inbox access.
How the layers combine
- An Account Administrator can access every project and every inbox on the account.
- Everyone else sees a project only if they have been added to it. Without project membership, they see nothing inside that project.
- Within a project, every member sees each inbox that is not restricted. A Viewer works with it as an inbox Writer would; an Editor or Admin as an inbox Admin would.
- A restricted inbox is narrower than its project. It is visible to Account Administrators, to the project's Editors and Admins, and to the users and teams granted access on the inbox itself.
- Where someone holds a role at more than one layer, the more permissive role applies.
Related pages
- Managing users and teams — invite people and group them into teams
- Manage project access — add users and teams to a project
- Manage inbox access — restrict an individual inbox
- API keys — account-level and inbox-level keys
Previous
Managing Users and Teams