Roles and access
The four workspace roles, what each is for, and where access is decided in the product.
Membership of a workspace carries one of four roles.
| Role | Intended for |
|---|---|
owner | The person who owns the account and its billing |
admin | Someone trusted with settings and spending |
editor | Someone who works on content |
viewer | Someone who needs to see the work without changing it |
What the roles separate
The important boundary is spending. Actions that cost money or change what the workspace is billed are restricted to the owner and admin roles. Editorial work is available to editors.
Adding people
Owners and admins invite people from Settings → Workspace → Team members. Choose the person's workspace role before sending. The email link lasts seven days, works once, and must be accepted while signed in with the address that received it. Pending invitations can be resent, renewed with a new secure link, have their role changed, or be revoked from the same screen.
Seats are unlimited on every paid plan. Inviting a teammate does not change billing, but their role applies to every current and future Project in the workspace. Owners cannot be removed or demoted from team settings, and a member cannot change their own role there.
What an invitation can refuse
Sending is checked in a fixed order, and each refusal names its own cause rather than failing generically.
- Your own email is not verified
You cannot invite anyone until your address is verified. Verify it and send again.
- The workspace has no paid subscription
The gate described above. Put a Project on a paid plan.
- Your sign in is stale
If the address on your account changed since you signed in, sign in again before sending.
- The account is disabled
A disabled account cannot send invitations at all. Contact support.
There are also daily caps, which exist to stop a mailbox being used as a delivery channel: 100 invitations per workspace per day, 100 per sender per day, and 5 to any single recipient per day across all of Blogged. Resending the same invitation has a 60 second cooldown, which is separate from the caps and clears on its own.
Invitations are sent from invites.blogged.dev, a dedicated sending domain that
is not the one billing email comes from. If a teammate cannot find the message,
that is the domain to search for and to allow.
If you need a boundary the current roles do not express, say so at hello@blogged.dev rather than working around it with a second workspace, which would split your billing and your content.
See the roles reference for the table in one place.