Developer docs

Permission matrix

Exactly which actions each role can perform across users, properties, billing, dashboards, and tracking. Use this as the canonical reference when you're deciding who needs which seat.

v3.0Updated May 2026

How roles work

datataste has four roles: Owner, Admin, Manager, Viewer. They exist at two levels:

  • Account level — applies across every property in the account. Available roles: Owner, Admin, Manager, Viewer. Every account must have at least one accepted Owner and can have multiple Owners.
  • Property level — applies to one specific property only. Available roles: Admin, Manager, Viewer.

A property-level role overrides the cascaded account-level role for that property. So a user who is Account Viewer can be promoted to Property Admin on a single property, and their access on every other property stays at Viewer. The Owner role only exists at the account level.

The matrices below show what each role can actually do. Cells marked If granted require an Owner to grant that user billing access first; cells marked Self only mean the action is allowed on the user's own account but not on anyone else's.

Account

Account-wide actions that change ownership, identity, or settings across the workspace. Owners manage Owner roles and destructive account actions; Admins can rename the account and view its settings.

ActionOwnerAdminManagerViewer
Manage Owner roles
Owners can add, promote, demote, or remove Owners. At least one accepted Owner must remain.
Delete account
Rename account
View account settings

Users

Owners can assign and manage every account role. Admins can invite, edit, and remove non-Owners, but cannot assign, change, or remove Owners. Managers can invite at the property level only; Viewers can only edit their own profile.

ActionOwnerAdminManagerViewer
Invite non-Owner account users
Assign the Owner role
By invitation or promotion.
Edit / remove non-Owner account users
Edit / remove Owners
At least one accepted Owner must remain.
Invite property-only users
On assigned properties.
Promote Viewers → Managers
Irreversible. Within assigned properties.
Edit own profile
Self onlySelf onlySelf onlySelf only

Billing

Subscription, invoices, and payment-method actions. Only Owners can grant billing access; once granted, Admins / Managers / Viewers gain the same billing capabilities marked with "If granted" below.

ActionOwnerAdminManagerViewer
Grant billing access
View invoices
Requires billing-access grant from an Owner.
If grantedIf grantedIf granted
Change plan / add-ons
Requires billing access.
If grantedIf grantedIf granted
Update payment method
Requires billing access.
If grantedIf grantedIf granted
Cancel subscription
If grantedIf grantedIf granted

Properties

Creating, deleting, and configuring properties — including the tracking snippet and first-party subdomain setup. Admins manage the property roster; Managers configure properties they're assigned to.

ActionOwnerAdminManagerViewer
Create property
Archive / delete property
Edit property settings
On assigned properties.
Install / rotate tracking snippet
Configure first-party tracking subdomain

Dashboards & data

What each role can do with the analytics output: viewing dashboards, editing layouts, and running the AI engine. Viewers get full read access (including AI queries) but cannot save or change anything.

ActionOwnerAdminManagerViewer
View dashboards
Viewer is read-only.
Edit dashboards
Save dashboard snapshots
Use the AI engine
Save AI dashboards