Team Roles & Permissions
Set up the right level of access for every person on your team so they can do their job without exposing sensitive settings.
Overview of Roles
MASK uses a role-based access control system. Every member of a workspace is assigned exactly one role that determines what they can see and do. There are nine roles: seven for your own team, and two for clients you share work with.
- Owner: Full control over the workspace, including billing and team management.
- Admin: The same permissions as the Owner, but cannot change or remove the Owner.
- Manager: All content, analytics and exports, branding, approvals and the audit log, but no control over members, billing, domains or workspace settings.
- Editor: Can create, edit, and delete links, bio pages, QR codes, and campaigns, but cannot change workspace settings or manage members.
- Analyst: Viewing and exporting analytics, and nothing else.
- Billing: Access to billing settings, invoices, and plan management. Cannot see or modify links, pages, or analytics.
- Developer: Access to API keys and webhook endpoints, plus links, bio pages and QR codes.
- Client Viewer: A client-facing role. Analytics only.
- Client Approver: A client-facing role. Analytics, plus approving work for publishing.
The Nine Roles in Detail
Owner: Every workspace has exactly one Owner. The Owner is the person who created the workspace and holds every permission, including billing, member management and domain configuration. The Owner role is fixed at creation: it is not in the list of roles you can assign, and there is no way to hand it to someone else.
Admin: Admins are trusted team leads who can manage day-to-day operations. Their permission set is identical to the Owner's: members, roles, domains, billing, branding, client access, the audit log, and all content. What separates them is that they cannot change or remove the Owner. Assign this role to department heads or project managers who need full operational control.
Manager: Managers run the work without running the account. They have full access to links, bio pages, QR codes and campaigns, can view and export analytics, manage branding, approve work for publishing, and read the audit log. They can see workspace settings but not change them, and they have no access to members, billing, domains or client management. This is the middle ground between Admin and Editor.
Editor: Editors are the content creators of the workspace. They have full create-read-update-delete access to links, bio pages, QR codes, and campaigns, and can view analytics. They cannot export analytics, change workspace settings, manage members, or view billing information. This is the right role for marketing team members, social media managers, and content creators.
Analyst: Analysts can view and export analytics, and nothing else. They do not get a read-only view of links, bio pages or campaigns. This role is for stakeholders who need the numbers and should not be able to touch, or browse, the content behind them.
Billing: The Billing role provides access to the billing and subscription section of the workspace, plus a read-only view of workspace settings. Members with this role can view invoices, update payment methods, change the subscription plan, and download receipts. They cannot see links, analytics, or any other workspace content. Assign this role to finance team members or office managers who handle payments.
Developer: Developers can create and revoke API keys and manage webhook endpoints, and they have full access to links, bio pages and QR codes plus a view of analytics. They do not get campaigns, exports, the audit log, billing or member management. This role is designed for engineers building integrations or automations on top of MASK.
Client Viewer: A client-facing role for someone outside your team. It grants analytics and nothing else, so a client can follow performance without seeing how the workspace is run.
Client Approver: The same analytics access as a Client Viewer, plus the ability to approve work for publishing. Use it when a client signs off on content before it goes live.
Permission Matrix
The table below summarizes which actions each role can perform. Use it as a quick reference when deciding which role to assign to a new team member. Creating, editing and deleting links is one permission, so no role can do part of it.
| Action | Owner | Admin | Manager | Editor | Analyst | Billing | Dev | Client Viewer | Client Approver |
|---|---|---|---|---|---|---|---|---|---|
| Create, edit & delete links | Yes | Yes | Yes | Yes | — | — | Yes | — | — |
| Manage bio pages | Yes | Yes | Yes | Yes | — | — | Yes | — | — |
| Manage QR codes | Yes | Yes | Yes | Yes | — | — | Yes | — | — |
| Manage campaigns | Yes | Yes | Yes | Yes | — | — | — | — | — |
| View analytics | Yes | Yes | Yes | Yes | Yes | — | Yes | Yes | Yes |
| Export analytics | Yes | Yes | Yes | — | Yes | — | — | — | — |
| Approve publishing | Yes | Yes | Yes | — | — | — | — | — | Yes |
| Manage branding | Yes | Yes | Yes | — | — | — | — | — | — |
| View audit log | Yes | Yes | Yes | — | — | — | — | — | — |
| View workspace settings | Yes | Yes | Yes | Yes | — | Yes | Yes | — | — |
| Change workspace settings | Yes | Yes | — | — | — | — | — | — | — |
| Invite, remove & re-role members | Yes | Yes | — | — | — | — | — | — | — |
| Configure domains | Yes | Yes | — | — | — | — | — | — | — |
| Manage client access | Yes | Yes | — | — | — | — | — | — | — |
| Manage billing | Yes | Yes | — | — | — | Yes | — | — | — |
| API keys & webhooks | Yes | Yes | — | — | — | — | Yes | — | — |
Two things the table deliberately does not list: deleting a workspace and transferring ownership. Neither is something any role can do, because neither exists as a control in the product.
Food Orders adds its own permissions on top of these. Owner, Admin and Manager can manage the menu and work the kitchen queue; branch management and ordering settings stay with Owner and Admin.
Inviting Team Members
To invite someone to your workspace, open the Team page and click "Invite Member." Enter their email address and select the role you want to assign. MASK will send an invitation email with a link to join the workspace.
If the person already has a MASK account, they will see the workspace in their dashboard immediately after accepting the invitation. If they do not have an account, the invitation link will guide them through account creation first and then add them to the workspace automatically.
Pending invitations are listed on the Team page with an "Invited" status badge. You can resend or revoke an invitation at any time before it is accepted. Invitations expire after 7 days, after which you will need to send a new one.
Only Owners and Admins can invite new members. Your plan caps the number of seats a workspace can hold; check Billing for your current limit.
Managing Access
Changing a role: Owners and Admins can change any member's role from the Team page. Click the role badge next to the member's name, select the new role, and confirm. The change takes effect immediately. The member's permissions are updated on their next page load. The Owner is the one exception: their role cannot be changed, and Owner is not offered as a role to assign.
Removing a member: To remove someone from the workspace, click the three-dot menu next to their name and select "Remove." The member will immediately lose access to all workspace content. Any links, bio pages, or QR codes they created remain in the workspace. Content is never deleted when a member is removed.
Leaving a workspace: There is no self-service way to leave a workspace. Ask an Owner or Admin to remove you. The Owner cannot be removed at all.
Audit log: Owners, Admins and Managers can view an audit log of member-related actions, including invitations sent, roles changed, and members removed. It is on the Audit page in the sidebar and is useful for reviewing access changes during security audits.
Best Practices for Teams
Follow the principle of least privilege: Assign the most restrictive role that still allows a person to do their job. If someone only needs to view reports, make them an Analyst rather than an Editor. If they only handle payments, use the Billing role instead of Admin.
Limit the number of Owners and Admins: These roles have the broadest access. In most organizations, one Owner and one or two Admins is sufficient. Having too many high-privilege accounts increases the risk of accidental configuration changes.
Review membership regularly: When someone leaves your company or moves to a different team, remove them from the workspace promptly. Stale accounts with active access are a common security gap.
Use separate workspaces for separate projects: If you manage multiple brands or clients, create a dedicated workspace for each one rather than granting everyone access to a single workspace. This keeps data isolated and makes it easier to manage who sees what.
Communicate role expectations: When you invite a new member, let them know what their role allows and what it restricts. This avoids confusion when they try to access a feature that is outside their permissions.