How roles work
datataste has four roles: Owner, Admin, Manager, Viewer. They exist at two levels:
- Account level — applies across every property in the account. Available roles: Owner, Admin, Manager, Viewer. Every account must have at least one accepted Owner and can have multiple Owners.
- Property level — applies to one specific property only. Available roles: Admin, Manager, Viewer.
A property-level role overrides the cascaded account-level role for that property. So a user who is Account Viewer can be promoted to Property Admin on a single property, and their access on every other property stays at Viewer. The Owner role only exists at the account level.
The matrices below show what each role can actually do. Cells marked If granted require an Owner to grant that user billing access first; cells marked Self only mean the action is allowed on the user's own account but not on anyone else's.
Account
Account-wide actions that change ownership, identity, or settings across the workspace. Owners manage Owner roles and destructive account actions; Admins can rename the account and view its settings.
Users
Owners can assign and manage every account role. Admins can invite, edit, and remove non-Owners, but cannot assign, change, or remove Owners. Managers can invite at the property level only; Viewers can only edit their own profile.
Billing
Subscription, invoices, and payment-method actions. Only Owners can grant billing access; once granted, Admins / Managers / Viewers gain the same billing capabilities marked with "If granted" below.
Properties
Creating, deleting, and configuring properties — including the tracking snippet and first-party subdomain setup. Admins manage the property roster; Managers configure properties they're assigned to.
Dashboards & data
What each role can do with the analytics output: viewing dashboards, editing layouts, and running the AI engine. Viewers get full read access (including AI queries) but cannot save or change anything.