Roles and permissions
A Workspace role controls what a member can do within that Workspace. It is separate from their role in an Organisation and from the Site's plan or integration capability. Choose the least authority needed for the person's job.
| Role | Typical responsibility |
|---|---|
| Viewer | Read accessible Sites, results and reports; no check-running or editing authority |
| Editor | Add and edit Sites, run checks and crawls, prepare Workbench drafts and generate reports |
| Reviewer | Approve or reject eligible saved drafts; the role does not grant draft editing |
| Publisher | Publish eligible approved work, such as a generated sitemap; the role does not grant editing or approval |
| Admin | Manage Workspace members, settings and Sites, with recipient management and report sending authority |
Permission examples
| Action | Viewer | Editor | Reviewer | Publisher | Admin |
|---|---|---|---|---|---|
| Read accessible results and reports | Yes | Yes | Yes | Yes | Yes |
| Run governance checks and crawls | No | Yes | No | No | Yes |
| Add or edit Sites | No | Yes | No | No | Yes |
| Edit Workbench drafts | No | Yes | No | No | Yes |
| Approve or reject drafts | No | No | Yes | No | Yes |
| Deploy an eligible generated sitemap | No | No | No | Yes | Yes |
| Remove Sites | No | No | No | No | Yes |
| Manage report recipients or send report email | No | No | No | No | Yes |
| Invite, change or remove members | No | No | No | No | Yes |
| Change Workspace settings | No | No | No | No | Yes |
The table describes Workspace roles alone. Organisation owners and administrators can have inherited authority over Workspaces in their Organisation hierarchy. A Workspace administrator is not automatically an Organisation administrator. The same person may be an admin in one Workspace and a viewer in another.
Activity and recipient privacy
Activity access depends on the surface and your authority; membership does not grant access to every Activity view or every person's audit records. Activity records report-recipient changes. Recipient email addresses are visible only to users authorised to manage report recipients for the affected Site. See Activity and audit.
Plans and supported actions
A role grants the ability to attempt an action; it does not enable a feature excluded by the plan or authorise a managed website change. Draft editing requires Pro or above, draft history Scale or above, and review/approval Agency or Enterprise. See Plan comparison and Managed changes.
If an expected control is absent, confirm the selected Workspace, membership, role, effective plan and Site capability with your administrator. Do not change another person's role merely to bypass a blocked action. Transferring Workspace ownership between members is not a supported self-service action; ask support if needed.