ZahlenwerkDocs

Roles & permissions

What Owner, Team Admin, Editor and Viewer may do, and how to limit access per tool.

Each team is its own workspace. One team's data is not visible to other teams, even if the same person is a member of several teams.

The four roles

PermissionViewerEditorTeam AdminOwner
Read data
Create, change, delete data
Invite and remove members, set roles and access
Audit log, usage, packages, billing, design, integrations, MFA requirement
Transfer ownership, archive or delete the team, own AI key, reset a member's MFA
  • Every team has exactly one Owner. The owner cannot be removed.
  • A Team Admin can only remove Editors and Viewers, and can only switch members between those two roles.

Seats

Your package includes a number of seats. The members page shows how many are taken, e.g. "3 of 5 seats".

  • Viewers do not take a seat. You can invite as many people with read access as you like.
  • Open invitations for other roles already reserve a seat.
  • Moving someone from Viewer to Editor needs a free seat.

Access per tool

Under SettingsMembers, open Choose their access for a member:

  • Every tool, following their role: the member may do everywhere what their role allows.
  • Choose per tool: for each tool (Directory, Assets, News, Agents & Tools, Bookkeeping, Banking) you choose No access, Read or Edit.

Tools without access disappear from the navigation.

Access through AI clients

Separately, you set what a member may do through connected AI clients (MCP):

SettingEffect
Same as their app accessSame as in the app.
Read-only, whatever the app allowsAI clients may only read, even if the member can write in the app.
No AI accessNo connection over MCP.

External members

Members can be marked as Internal or External. External members get a badge and, optionally, an end date. On that date they are removed from the team automatically, which is handy for tax advisors or auditors with time-limited access.

On this page

EN
EnglishDeutsch