Roles and Permissions

Permissions in an organisation come from two places that add together: a workspace role that applies to the whole organisation, and per-podcast access to individual shows. Nothing ever takes access away — a person can only end up with more than their role gives them, never less.

Workspace roles

Every member of an organisation holds exactly one workspace role. You can see and change it in the Role column on Settings → Team, or on a member's own page.

Owner

Full control of the workspace. Owners can do everything an Admin can, plus:

  • Manage billing, subscriptions and credit purchases
  • Create and manage the organisation's API keys
  • Make someone else an Owner (only an Owner can hand out ownership)
  • Delete the organisation

The person who creates an organisation is its first Owner. You can have more than one.

Admin

Everything except billing, ownership and deleting the workspace:

  • See and manage every podcast in the workspace, without being added to it
  • Add new podcasts to the workspace, and remove them from it
  • Run reports and enhance audio, including on directly uploaded files
  • Invite people, remove people, and change anyone's role except an Owner's
  • Rename the organisation
  • Edit any podcast's settings and its report notification list

Admin is the right role for a producer or team lead who runs the shows day to day but should not see billing.

Member

A Member starts with no podcast access at all. They see only the podcasts they have been added to, and what they can do on each one depends on the role they were given there.

By default a Member cannot:

  • See podcasts they have not been added to
  • Add a new podcast to the workspace
  • Run reports or enhancements on directly uploaded files
  • Invite or remove people, or change roles

Members can be granted the ability to run reports and enhance audio — see "Workspace permissions" below.

Rules that always apply

  • A workspace must always have at least one Owner. The last Owner cannot be demoted or removed — promote someone else first.
  • Only an Owner can give someone the Owner role. Admins can set any other role, on anyone who is not already an Owner.
  • Nobody can remove themselves from a workspace from the team page.

Per-podcast roles

These are the roles that are linked to a specific podcast. They are what gives a Member access to a show, and they are managed from that show's own settings page under "Report notifications" (see Podcast Access and Report Emails).

There are two:

Manager

Can see this show, run reports for it, and edit its settings and its notification list. A Manager effectively runs one show without having any authority over the rest of the workspace.

A Manager cannot add or remove podcasts from the workspace, and cannot run reports on uploaded files — those are workspace-level actions.

Viewer

Can see this show and its reports, and nothing else. Viewers cannot change any settings and cannot start anything that spends credits.

Viewer is the default when you add someone to a podcast, so you never grant more than you meant to.

Extra permissions on a single podcast

If Viewer is too little but Manager is too much, you can tick individual extras for one person on one show. From the podcast's notification list, click the "Extra…" link on their chip. Two are available:

  • Edit this podcast's settings
  • Edit this podcast's notification list

Greyed-out lines are the ones their role already covers. Extras apply to that podcast only.

Owners and Admins do not appear with meaningful per-podcast roles — they already hold everything on every show. If they are on a podcast's list, it is because they want its report emails; the chip shows their workspace role next to it so the "Viewer" label is not misread as a restriction.

Workspace permissions

Running a report and enhancing audio both spend the workspace's shared credit balance, and both can be done on a directly uploaded file that belongs to no podcast at all. For those two reasons they are granted per person for the whole workspace, not show by show:

  • Run reports (including on uploaded files)
  • Enhance audio (including uploaded files)

Owners and Admins hold both automatically through their role. For a Member, an Admin or Owner ticks them on the member's own page — Settings → Team → their name → Workspace permissions.

A Member who holds one of these can use it on uploaded files, and on any podcast they can already see. It does not give them access to shows they were not added to. So a Viewer who is granted "Run reports" can run reports on the shows they are on, and nowhere else — a combination the roles alone cannot express.

A Manager grant already includes running reports and enhancing audio for that one show, so you do not need to also grant the workspace permission unless you want them to work on uploads or on other shows they can see.

Worked examples

  • A producer who runs everything but must not see billing — Admin.
  • A freelancer working on one show — Member, plus a Manager grant on that show.
  • A client or stakeholder who should only read results — Member, plus a Viewer grant on the relevant shows. If you would rather not add them to the workspace at all, share individual reports instead.
  • An assistant who should run reports on the shows they follow, but change nothing — Member, Viewer grants on those shows, and the "Run reports" workspace permission ticked on their member page.
  • Someone who should keep a show's episode list tidy but not run anything — Member, Viewer grant, plus the "Edit this podcast's settings" extra on that show.

Quick reference

Actions only an Owner can take:

  • Billing, subscriptions and buying credits
  • Organisation API keys
  • Granting the Owner role
  • Deleting the organisation

Actions an Owner or Admin can take:

  • See and manage every podcast in the workspace
  • Add podcasts to the workspace and remove them from it
  • Invite and remove members, and change roles below Owner
  • Rename the organisation
  • Run reports and enhancements on anything, including uploads

Actions a Member can take:

  • See the podcasts they have been added to
  • On a show where they are a Manager: edit its settings, edit its notification list, and run reports or enhancements for it
  • Anything their extra permissions or workspace permissions add
  • Mute or unmute their own report emails for any show they are on