Company and team roles

Roadmap Flow has five company roles and three team roles. They are deliberately narrow, and two of the separations are the ones people misread, so they are worth two minutes before you start handing roles out.

The five company roles

  • Company owner. One per company, always. Owns the company record, can do everything an administrator can do, and is the only person who can hand the company to somebody else. The owner cannot be suspended, removed, unlicensed or have their role changed — those actions are refused until ownership is transferred.
  • Company admin. Manages people, teams, roles, invitations and company settings. Can read the audit log.
  • Billing admin. Manages the subscription, the seat quantity and the invoices. Can read the audit log.
  • Member. The ordinary role. Uses a licensed seat, belongs to teams, manages nothing.
  • Viewer. Read-only, and unlicensed by default, so viewers do not count against your purchased seats.

The two separations people misread

A company admin does not get billing. Managing people and managing money are different jobs. Someone who can add a person to the company cannot change your seat quantity, cannot open the Stripe portal and cannot see your invoices. If you want one person to do both, give them the owner role by transferring ownership, or give them both jobs by making them the billing admin as well — a person holds one company role at a time, so in practice you make them the owner.

A billing admin does not get roadmap content. This one is stronger than it looks: a billing admin is refused access to roadmap content even when they are holding a licensed seat. It is enforced by the server, not by hiding a button. A finance contact can manage the subscription and never be able to read the roadmap.

If those two rules seem inconvenient, they are the reason an enterprise IT reviewer signs the form.

The three team roles

Team roles apply inside one team and never affect billing.

  • Team admin. Manages that team: its name, its shared workspace path, and who is in it with which team role. A team admin of one team has no authority over another team.
  • Editor. The ordinary team role.
  • Viewer. Read-only within the team. Note this is a team role and is separate from the company viewer role — a company member can be a viewer of one team and an editor of another while still holding their licensed seat.

A company admin administers every team automatically and does not need a team role to do it.

Who can open which console page

Anyone who is an active member of your company can sign in to the console. What they can then reach depends on their role:

  • Overview — everyone.
  • People, Invitations, Administrators, Company settings — company owner and company admins.
  • Teams — company owner, company admins, and anyone who is a team admin of at least one team.
  • Seats and billing — company owner and billing admins.
  • Audit log — company owner, company admins and billing admins.

Pages a role cannot reach appear greyed out in the navigation and cannot be opened. That is a courtesy, not the security boundary: every management endpoint re-checks the role on the server, so nothing is protected by a hidden button.

Related guide pages

Team Updated in 0.1.10

← Back to the Field Guide