What it does
Every organization member holds exactly one of four roles. Two underlying abilities decide almost everything: can manage resources (sites, updates, backups, security actions, clients) — every role except Viewer — and can administer the organization itself (billing, team, notification routes, connector rollouts) — Owner and Admin only.
The matrix
| Capability | Owner | Admin | Tech | Viewer |
|---|---|---|---|---|
| View sites, updates, backups, security, uptime, performance, reports, activity | ✓ | ✓ | ✓ | ✓ |
| Add a site, run updates, back up now, ignore/resolve security findings | ✓ | ✓ | ✓ | — |
| Restore a site, connector self-update / revert / canary pin | ✓ | ✓ | — | — |
| Billing Suite and your WPClientHub plan | ✓ | ✓ | — | — |
| Invite / remove team members, change roles | ✓ | ✓ | — | — |
| Notification routes ("who else should hear about this") | ✓ | ✓ | — | — |
| Offsite storage credentials | ✓ | ✓ | — | — |
| Help Desk: work requests, draft/send estimates, diagnose | ✓ | ✓ | ✓ | read-only |
| Eligible as a Help Desk default assignee | ✓ | ✓ | ✓ | — |
| Own notification preferences | ✓ | ✓ | ✓ | ✓ |
| Ops console (ThirteenBytes staff only) | n/a | n/a | n/a | n/a |
Ops console access is a separate, entirely unrelated staff-only flag — it has nothing to do with your organization role, even for an owner.
How to
- Go to Team to see every member's role.
- An owner or admin changes a role inline from the same page.
- A button a role can't use is shown disabled with a reason, rather than enabled and then failing — if something looks available but doesn't work, the server enforces the same rule either way.
Troubleshooting
A Viewer sees "Add site" or "Update" enabled
These now disable with an explanatory tooltip for a Viewer — if you still see an enabled control that fails, it's worth a hard refresh.
A Tech can't restore a site or manage connector rollouts
That's intentional — those two actions require Owner or Admin specifically, stricter than the general "can manage resources" bar Tech otherwise clears.