Account & team
One login can belong to many projects, and the member role sets what it can do in each one. Adding a teammate does not require handing out the website snippet or an API key.
- Profile, password, language, theme, and account deletion: ConsoleAccount.
- Project members: ConsoleConfigurationSettingsMembers. The account that created the project is the owner.
- API keys: ConsoleConfigurationSettingsAPI keys. See Security. Creating a project: Accounts, projects & sources.
- When the same people join several projects, use account-level user groups for bulk grants. See User groups.
Roles
| Role | Console label | What they can do |
|---|---|---|
| Owner | Owner | Everything, including deleting the site. An invite cannot create another owner, and the owner cannot be changed to another role or removed |
| Admin | Admin | Change settings, invite members, change chat settings, and run compliance actions |
| Analyst | Analyst | Read reports, create goals, and take chats |
| Viewer | Viewer | Read-only reports. No inbox |
| Agent | Agent only | Inbox only. No analytics reports |
People who can open the inbox are the owner, admins, analysts, and agents. Headcount is capped by the analytics plan's members-per-site limit, which defaults to 1 on Free. See Plans & quotas. Changing a viewer into any other role also checks the chat agent quota.
Invites and access scope
An invite takes an email that already has an account. The role can be admin, analyst, viewer, or agent. An unknown email returns "this email is not registered". An email that is already a member returns a conflict.
The owner is not scoped. An admin can narrow everyone else:
- Channels, platforms, and hostnames: reports keep only those rows.
- Hidden property keys: a user property and an event property with the same name are both hidden. Referencing them in an analysis returns 403. A member with hidden properties cannot use restricted SQL or raw export.
- A per-member mask floor: combined with the role policy and any property-level mask, the strictest level wins.
Each list holds at most 50 entries. Clearing scopes restores that role's default, which is no row filter.
Three mask levels
Display masking has three levels: none, partial, and full. Partial keeps the first character and the domain of an email, the last four digits of a phone-like string, and the ends of other strings. Full shows asterisks.
Defaults: admins see both identifier classes in the clear; analysts see direct identifiers partially masked and indirect identifiers in the clear; viewers see direct identifiers fully masked and indirect identifiers partially masked. The owner is not on this role table. An admin can change the role policy on the members page. Stripping values before they are stored is a separate layer. See Privacy & compliance.
Two-step verification
The server uses TOTP. After the password succeeds on an account that has it on, the login response is a ticket valid for 5 minutes, not the session cookie. A 6-digit authenticator code or a recovery code exchanges the ticket for a session. A code for a given time step can be used once. Turning it off and regenerating recovery codes both require proving identity again.
An operator can require two-step verification for every account. It is not required by default. Enable, disable, and recovery codes are the account-security routes under /auth/mfa. When a code is required, login returns mfaRequired and the ticket.
Deleting the account deletes your sites. The console says they are purged after 30 days. Deletion asks for the password again.
FAQ
Why is the invite button unavailable? The current role is not owner or admin.
My teammate did not get an invite email. Why? Invites do not send a sign-up mail. They register with that email first, and then you add the email on the members page.
Why can a viewer export email addresses? Check whether the role's mask policy was set to none, and whether that member has a personal floor of none. Viewers default to full masking on direct identifiers.
User groups
A user group is not a new kind of permission: when you save, the system writes member × project × role into each project's member list, and inside a project they appear as ordinary members. Inviting a single member and limiting their scope still happens in project settings. See Account & team.
ConsoleAccountMembers & user groupsThis item is in the Account group in the left menu when you are not inside a project. A group belongs to the account that created it; others cannot see your groups.
How to configure
A group contains:
- Name, required, up to 60 characters. Description, up to 300.
- Member emails: one per line or comma-separated, up to 500, and each must be a registered email. If any email is not registered the whole save fails and the first few are listed.
- Projects & roles: up to 200 projects, one role each: admin, analyst, viewer, or agent only. Owner cannot be granted. You can only choose projects where you are owner or admin; the server rejects others.
Saving requires at least a name, one member, and one project.
How applying and revoking work
- New members. If a member is not in the project, they join with the role set in the group.
- Existing members only go up. If a member is already in the project, the role changes only when the group's role ranks higher. Equal or lower roles are left alone. The order is agent only, viewer, analyst, admin. The owner is never touched.
- Revoking. When you remove a member or a project from a group, or delete the group, the matching member × project pairs are deleted from the project member list unless another group of yours still covers them. Owners and you yourself are never removed.
- Manually added members are revoked too. Revoking does not check whether someone was first invited by hand. If a person was invited manually and is also in a group, removing them from the group removes them from that project. Use groups as the only source of access for those projects.
How to use it
- Click New group, then enter a name and member emails.
- Under Projects & roles, click Add project and pick a role for each project; the default is viewer.
- Save. Saving also applies the group, and the page says how many members were added and upgraded.
- To write the grants again later, click Apply to projects. For example, if someone's role was lowered by hand, applying restores a higher group role, but never lowers a higher one.
- Click edit to change members or projects. Click delete and confirm; members granted by this group and not covered by another group lose that access.
Example: put three analyst colleagues in one group and grant two projects, analyst on one and viewer on the other. When someone new joins, add their email to the group.
Access & limits
Groups are visible and editable only by your own account, regardless of project roles. To grant a project you must be its owner or admin. When a group is applied, the server does not check the plan's members-per-site limit; that limit is only checked when inviting inside a project (see Plans & quotas), so check headcount yourself before a bulk grant. Each time project members actually change, the project's audit log gets a group-apply or group-revoke entry.
FAQ
Why does it say I cannot grant a project? You are not an owner or admin there. Ask the owner to make you an admin, or remove that project from the group.
Why does it say an email is not registered? Groups only accept registered accounts; ask the person to sign up first.
I changed a role in the group. Why did the project not change? Existing members only go up. To lower a role, change it by hand on the project's members page, or remove the person from the group and invite them again manually.
Why did a member disappear? Check whether they were removed from a group or the group was deleted. Revoking ignores how they were first added.