How to build a Client Viewer role (read-only dashboards)

Build a read-only Client Viewer workspace role so clients can see RankWatch dashboards without mutating data.

Prerequisites

  • Org owner access to Role Management

A Client Viewer role is the standard agency pattern for client portal access: dashboards and reports to read, almost nothing to change. Billing and Role Management remain org-owner only.

Role permissions hint in RankWatch organization settings
Use Roles to grant read permissions without keyword, project, or invite write rights.

Steps

  1. Open Organization settings → Roles as org owner.
  2. Create a role named something clear, for example Client Viewer.
  3. Enable view permissions for the surfaces clients should see — typically projects, rankings, competitors, backlinks, GSC, and report downloads as the product allows. Prefer view-only over edit or manage.
  4. Explicitly omit write permissions: keyword edits, project create/update/delete, competitor manage, GSC connect, invites, alert rule edits, and tool job starts (unless you intentionally allow a tool).
  5. Do not try to grant organization-owner powers (billing, notification admin, Role Management) — those stay with the org owner.
  6. Save, then invite the client into the correct workspace with this role (invite a client as read-only). Spot-check that Add keywords / settings mutations are blocked.

Outcome

Clients can review SEO (and AI (when included)) dashboards without changing tracking. Pair with whitelabel branding when you hand them a branded portal experience.