Skip to content

Roles and permissions

Each account membership has one role. Owner is the account’s protected ownership relationship backed by an Admin membership, not an assignable fifth role or platform administrator.

Capability Viewer Billing Editor Admin / Owner
View monitoring Yes Yes Yes Yes
Read operational credentials No No Yes Yes
Manage checks and locations No No Yes Yes
Manage dashboards and ordering No No Yes Yes
Manage groups, channels, rosters and schedules No No Yes Yes
Post/remove incident updates No No Yes Yes
Publish status pages No No No Yes
Manage public branding No No No Yes
Manage integrations and automation connections No No No Yes
Manage billing No Yes No Yes
Manage account settings and non-owner members No No No Yes
Transfer ownership or delete account No No No Owner only

Owner and Admin have the same ordinary administrative access; the ownership exceptions remain protected. Customer roles do not grant platform-staff access or access to other accounts.

Operational credentials include heartbeat ingestion URLs and verification values. Read-only monitoring does not imply permission to retrieve them.

Automation needs both a grant scope and the issuing user’s current account capability. Separate scopes apply to check writes, alert assignment and dashboard assignment. Giving checks:create does not automatically authorize all nested assignments.

If a control is missing, first confirm the selected account and your role. Plan quotas are independent of permissions: an Admin can still hit a quota.