docs · workspace

Teams & clients

One workspace holds your sites, your team and your billing. Agencies run each client in a workspace of its own, under one roof and one invoice.

Roles

RoleCan
OwnerEverything, including billing, deletion and ownership transfer.
AdminEverything except billing and deleting the workspace. Scale and Agency plans.
EditorEdit and publish banners, look after cookies and trackers, run scans.
AnalystRead consent records, analytics and exports. No publishing. Scale and Agency plans.
DeveloperAPI tokens, webhooks and install checks. No billing or team changes. Scale and Agency plans.
ViewerRead-only across the sites they can see.

Per-site access narrows any member to specific sites (Scale and Agency). Every role is enforced on the server as well as in the interface.

Invitations and seats

Invite by email; invitations are valid for seven days and can be resent or revoked. Members and pending invitations both take a seat, counted against the plan's seat limit.

Client workspaces (agencies)

On the Agency plan a workspace can create client workspaces: separate workspaces with their own sites, team and data, billed through the parent. Twenty are included; every further one is added to the invoice as an add-on the moment it is created. Open a client to work inside it (clearly marked, and read-only where your role says so), and move a site into a client workspace when a project graduates. Presets let you keep one banner design and apply it across many sites at once.

Activity

Everything anyone changes, publishes or exports is a line in the activity log: who, from where (dashboard, CLI, API or MCP), and what changed. The full log with filters is a Scale feature; recent activity is visible on every plan.