Who can see what — roles and permissions overview
Workspace roles control day-to-day product access; org owners alone manage billing, roles, whitelabel, and notification settings.
Access in RankWatch is role-based. Members see only workspaces they belong to, and within a workspace they only get the permissions on their assigned workspace role.
Two scopes
Workspace role (day-to-day)
Assigned on invite as the teammate’s workspace role (workspace role). Controls keywords, projects, GSC, competitors, backlinks, AI analytics, tools jobs, reporting, and invites — depending on which permissions the role includes.
Custom roles can only include workspace-assignable permissions. organization-owner controls (billing, org profile, role CRUD, notifications delivery) are not granted through workspace roles.
Org owner (account)
Organization owners manage package and billing, Role Management, whitelabel, org profile, and organization notification / email-delivery settings. These stay owner-controlled in the product model even when a workspace role looks powerful.
Invites
- Required: workspace role for the target workspace.
- Optional: org role (defaults to org member with no account permissions).
- Clients invited as read-only should use a Client Viewer–style role with dashboard read permissions only.
Starter recipes
| Persona | Intent |
|---|---|
| Client Viewer | Read dashboards for assigned client projects; no mutations |
| SEO Executive | Keywords, tracking, alerts, day-to-day SEO ops |
| Agency Manager | Projects and invites across client workspaces; no billing |
Details: Recommended role recipes and Permission model overview.