Team, roles, and organizations
Four roles from viewer to owner, one team per account, and organizations as folders for client sites: who can do what, how invites work, and what grouping changes — and what it does not.
One team per account
Your account is the unit that holds everything: the subscription, the team, the organizations, and the sites inside them. Everyone you add joins the account itself, with a single role. Owners and admins always have the whole account. A member or a viewer has either the whole account or only the organizations named on their seat, and sees just the sites in those; there is no per-site access. That is the most useful fact on this page, and most of what follows falls out of it.
The role ladder
Four roles, ranked. From the top:
- Owner — everything, including billing and granting ownership. Only an owner can start or change the subscription, redeem a coupon, delete a site outright, or change how long consent records are kept.
- Admin — manages sites and the team: inviting people, changing roles, removing members, archiving a site, changing a site's domain. Admins cannot touch billing and cannot act on owners.
- Member — the working role. Members run scans, categorize and approve cookies, publish banners and documents, add sites, and create and arrange organizations.
- Viewer — read-only. A viewer can open every page, including Team and Billing, and can change nothing.
Notice where the lines fall. Publishing a banner is member work. Deleting a site is owner work, and archiving sits between them: an admin can archive, because the site's records survive it. Deleting unmakes the evidence, so it is held at the top of the ladder.
The rules underneath
Three rules run through every team action, and each is checked against the database on every request, never against what the browser claims:
- You cannot act on someone who outranks you. An admin cannot change or remove an owner, and only an owner can invite one.
- You cannot hand out a role above your own.
- You cannot change your own role or remove yourself. Self-service promotion and accidental lockout are the two mistakes this closes off.
One more rule sits above those: the account always keeps at least one owner. Demoting or removing the last owner is refused by the application, and refused again by a database constraint in case the application is ever wrong.
How invites work
An invite is an email address and a role. UserGuard emails the person a link and shows you the same link, so you can pass it along another way — if the email never lands, the link alone is enough. Links expire after 7 days.
- The link is shown once. The server stores only a hash of it, so nothing can resend the original. If a link is lost, regenerate the invite: a fresh link is issued and the old one stops working. Revoking cancels the invite entirely.
- One open invite per address. Inviting the same address again replaces the earlier invite, and the earlier link dies with it.
- Accepting is signing in. The invited person signs in to an existing UserGuard account or creates one on the spot; an account created this way is bound to the invited address. If they already joined your team some other way in the meantime, accepting the invite never overwrites the role they hold.
Organizations are folders, not workspaces
Organizations group the sites inside one account: the account holds the billing and the team, organizations hold the grouping, and every site lives in exactly one organization. An agency puts each client's sites in its own organization, names it after the client, gives it a color, and the dashboard keeps the clients apart.
Be clear-eyed about what an organization is not. It is not a workspace: the team and the billing stay on the account, and everyone holds one role across the whole of it, so an admin on the account is an admin over every organization in it. What an organization can do is bound what a member or viewer sees. A seat limited to organizations shows only the sites in the ones named on it, while owners and admins see every organization. A whole-account seat picks up organizations added later; a limited seat picks up none until an admin adds it on that organization's Members page. If even your owners and admins must never see two clients side by side, the boundary you need is two accounts, not two organizations.
Every account starts with one organization, and the last one cannot be deleted — sites have to live somewhere. An organization that still holds sites cannot be deleted either, archived sites included; move them first.
Moving a site between organizations
Any member can move a site to another organization on the account. Nothing else changes: scan history, published documents, consent records, and the bill are untouched, and the move lands in the account's audit log.
What organizations change, and what they do not
Organizations change presentation: how sites are grouped, named, and colored. They do not change pricing. Volume discounts count every live site on the account, whichever organizations those sites sit in — ten clients split across ten organizations pay the same per-site rate as ten sites in one. The tiers themselves are in Billing, refunds, and how pricing works.