Team & roles
Roles map onto the same three bands the API uses. There is no second permission vocabulary to keep in your head.
Members (1)
Last active is drawn from the activity log, so it counts API use as well as dashboard visits.
Just you so far
Invite the people who will act on what this finds — usually whoever owns the site, and whoever reviews the pull requests.
| Member | Role | Bands | Can approve | Last active | |
|---|---|---|---|---|---|
| PRPriya Ramanpriya@acme.com | owner | readdraft | 5h ago |
Invite
They get read access until you raise it.
What each role can do
Four roles, because five is where people stop reading the table.
Billing, key issuance, and approval of gated tasks.
Everything except billing.
Can draft fixes and add prompts. Cannot approve them.
Read-only across every screen.
Audit
Every approval, rejection and key issuance is written to the activity log with the person's name against it. That log is the record a security review actually reads.