DOCS

Roles and permissions reference

Complete matrix of what each workspace role can do.

Role overview

Every workspace member holds a role. The system seeds these built-in roles per workspace:

RoleSummary
OwnerFull access including billing, ownership transfer, and workspace deletion. One per workspace.
AdminFull access, including billing. Can manage all team members. Cannot transfer ownership or delete the workspace.
Member (editor)Create and manage all technical resources. Read-only view of billing and settings; cannot manage the team or change plans.
ViewerRead-only access across the workspace.

Owner and Admin bypass fine-grained permission checks and have full access. Members hold the editor system role; viewer and editor are seeded as built-in system roles alongside admin. For access profiles beyond these, use custom roles. See Custom roles below.

Permissions matrix

Monitors

ActionOwnerAdminMember
View monitorsYesYesYes
Create monitorYesYesYes
Edit monitorYesYesYes
Pause / resume monitorYesYesYes
Delete monitorYesYesYes

Heartbeats

ActionOwnerAdminMember
View heartbeatsYesYesYes
Create heartbeatYesYesYes
Edit heartbeatYesYesYes
Delete heartbeatYesYesYes

Incidents

ActionOwnerAdminMember
View incidentsYesYesYes
Acknowledge incidentYesYesYes
Resolve incidentYesYesYes
Add note to incidentYesYesYes

Notification channels

ActionOwnerAdminMember
View channelsYesYesYes
Create channelYesYesYes
Edit channelYesYesYes
Delete channelYesYesYes
Send test notificationYesYesYes

Alert routing rules

ActionOwnerAdminMember
View rulesYesYesYes
Create / edit / delete rulesYesYesYes

On-call schedules

ActionOwnerAdminMember
View schedulesYesYesYes
Create / edit / delete schedulesYesYesYes
Create schedule overrideYesYesYes

Status pages

ActionOwnerAdminMember
View status pagesYesYesYes
Create / edit / delete status pagesYesYesYes
Manage subscribersYesYesYes

Team management

ActionOwnerAdminMember
View membersYesYesYes
Invite memberYesYesNo
Change member roleYesYesNo
Remove memberYesYesNo

Billing

ActionOwnerAdminMember
View billing / invoicesYesYesYes
Change plan / cancelYesYesNo
Update payment methodYesYesNo

API tokens

ActionOwnerAdminMember
Create own tokensYesYesYes
Revoke own tokensYesYesYes
View team token metadataYesYesNo
Revoke any tokenYesYesNo

Workspace settings

ActionOwnerAdminMember
View settingsYesYesYes
Edit workspace settingsYesYesNo
Configure SSOYesYesNo
Transfer ownershipYesNoNo
Delete workspaceYesNoNo

Custom roles

The built-in roles cover most teams, but you can define custom roles for finer-grained access: an incident-only responder, or any other scoped profile your organization needs.

  • Manage them under Settings > Roles. Custom roles are stored with is_system = false, which distinguishes them from the built-in system roles (admin, editor, viewer) that are seeded per workspace with is_system = true.
  • Assign a custom role when you invite a teammate: it appears in the role dropdown under a Custom roles group, alongside the system roles.
  • A built-in Viewer role already provides read-only access, and editor is the system role behind Member. Custom roles let you go beyond these, for example a responder-style profile scoped to incidents only.

Changing a member's role

Only Owner and Admin can change roles. Once a member has joined, their system role can be switched between Admin and Member. You cannot assign or remove the Owner role through this path; use Settings > Team > Transfer ownership.

See also

Was this page helpful?