Role templates
Starter workspace role packs and how to customize them.
RankWatch ships role templates (role packs) you can clone when building custom workspace roles. Templates group sensible defaults for agencies, brands, and marketing leads.
Workspace vs account in the builder
The role builder UI only lists workspace-assignable permission groups. You will not see billing, notification, or RBAC administration keys there — those remain owner-only regardless of template name.
When editing a template-derived role:
- Open Organization settings → Roles
- Duplicate a template or create a blank role
- Toggle workspace permissions (projects, keywords, reports, etc.)
- Save — members pick up changes on next API authorization check
Suggested mappings
| Persona | Start from | Usually adjust |
|---|---|---|
| SEO operator | seo_marketing_head_v1 | Keyword + report permissions |
| Client read-only | Custom minimal role | Only project.read, report.read |
| Project lead | brand_owner_v1 | Add project.update, remove delete if needed |
Invites
Team invites require a team_role_key. The invited user receives the permissions of that role in the target workspace only.
Org-level org_role_key on invites defaults to org_member with zero elevated permissions — workspace access is driven by the team role.