Skip to content

Learn · Concepts

Roles and access

Who can see what, and why — access is always legible.

Checked against the product on · written for people who run the account

Five kinds of people use the platform. Each one sees exactly what their role grants, and the server checks the grant on every request.

The five roles.
RoleSeesChangesTypical holder
OwnerEverything in the organization.Everything, including billing and deletion.The person who opened the account.
AdminEverything in their work areas.Rules, feeds, packs, keys, and people.Whoever runs the work area day to day.
ReviewerWatch, reviews, and records in their work areas.Review outcomes.The person who decides held calls.
ReaderWatch, reviews, and records in their work areas.Nothing.An auditor, or a stakeholder watching.
DeveloperDeveloper tools and the docs.Their own sandbox keys.Someone writing code against the API.
console.dmzagent.com/team

Prove

Team & billing

1PeopleRolesPlan
2
PersonRoleWork areasAdded
dana@example.comAdminAll2026-06-02
sam@example.comReviewerplant-east2026-06-14
lee@example.comReaderplant-east2026-07-03
3Manage planInvite someone
Figure. Role and work areas are set per person, and both are visible on the roster. The team screen: members with their role and work areas, and the plan summary.
  1. Open Team & billing to see who holds what.1

  2. Read the work areas column.2

    A role is scoped to work areas. A reviewer in one work area sees nothing in another.

  3. Select Invite someone to add a person at a role.3

Where the boundary sits

  • Access is refused unless a rule grants it, and the check runs on the server on every request.
  • Separation between accounts is enforced at the data layer, beneath the screens.
  • Every grant, change and removal lands in the workspace audit log with the actor on it.
  • Our operators see account health and billing. Your watched data and your conclusions sit outside that boundary, and every operator action lands in a separate trail.
Safe by default. Passkeys are available on platform-hosted origins, and an organization can require them. A passkey is bound to this site, so it cannot be replayed against a lookalike.