Teams, roles & permissions
Every app belongs to an organization. Solo, you're the only member; as a team, you invite people and assign roles that decide who can build versus who can ship and manage. Apps are shared across the org — not owned by one person.
Roles
| Role | Can do |
|---|---|
| Owner | Full control. Everything an admin can do, plus delete apps and manage the plan, seats, and billing. |
| Admin | Manage apps and the team: create apps, attach/detach resources, manage env & domains, schedule cron, merge pull requests, transfer apps, and invite or remove members. |
| Member | Sees every app in the team, but needs a per-app grant to work on one: Can view (files, versions, data), Can edit (change code, open pull requests, deploy previews), or Admin (ship it). No grant yet? They request access from the app's page and an admin approves. Can't change org-level settings. |
| Guest | Limited collaborator. Sees no apps by default — an admin grants access to specific apps (great for a contractor on a single app). Guests are free and don't use a paid seat. |
main and changing an app's settings always require admin on that app — an org admin/owner, or a member holding an app-admin grant.Per-app access levels
Every app has its own access list (the app page's App access card). A member with no grant still sees that the app exists in the team — name only — and can request access from the app's page; the team's admins get notified and approve or decline in one click.
- Can view — read files, versions, deploy history, and browse the app's data. Good for stakeholders and reviewers.
- Can edit — everything in view, plus change code, create branches, open pull requests, and deploy previews. The day-to-day builder level.
- Admin — everything, on this one app: merge its pull requests, deploy to production, manage env, domains, resources, and cron. (Per-app admin grants are a Team-plan feature; view and edit grants work on every plan.)
Inviting teammates
Admins and owners invite people by email from the dashboard. An invite carries a role (member, admin, or guest); the invitee accepts via the link and joins the organization. You can change a pending invite's role before it's accepted, and remove members later.
When someone is removed from the org, their personal preview deployments and playground data for the org's apps are torn down automatically. Shared branch previews stay with their branch — they clean up when the branch is merged or deleted.
Granting and requesting access
- Grant directly — an org owner/admin picks a teammate and a level on the app's App access card, or asks the assistant: “give ola@firma.no edit access to this app”.
- Request flow — a member opens an app they don't have access to, taps Request read/edit access, and every org admin is notified (in-app + email). Approving creates the grant immediately.
- Members who create apps — if an owner/admin turns on “Members can create apps” in Team settings, a member who creates an app automatically becomes its app admin, so they can build and ship that app end-to-end (merge & deploy) without being a team admin.
- Guests — unlike members, guests don't even see that other apps exist: only the apps they've been granted. Great for a contractor on a single app. Guests are free, but the number you can add is capped at twice your billable seats, and their deploys draw from the team's shared pool.
How this maps to merging
The role split is what makes the branch & pull-request workflow safe: a member's work reaches production only when someone with admin rights on that app reviews and merges the PR — an org admin, or a member granted app-admin on it. main stays protected no matter how many people are building.
Billing & seats
- The individual plans (Free, Basic, Premium) are single-seat — for one builder.
- The Team plan is billed per seat, with a few seats included in the base (more on Team Premium than Team Basic); beyond that, each extra member is an added seat. Guests don't use a seat. Adjust seats and see pricing on the pricing page.
- View and edit grants work on every plan; per-app admin grants (a member who can merge & ship one app) are a Team-plan feature.