Roles & Permissions
Everyone you add to a team gets a role and, optionally, a seat. Those are two different decisions, and keeping them apart is what lets you invite a whole agency without paying for a whole agency.
- A role is what a person is allowed to do — view reports, build them, set up connections, run the team, change the plan.
- A seat is whether they can change anything at all. A member without a seat can see everything their role allows and change none of it.
Every current plan includes unlimited users, so you can invite your whole team and your clients. Roles and seats are how you decide what each of them can do once they are in.
The One-Paragraph Version
Invite everyone who needs to see the work. Give a seat to everyone who needs to do the work. If someone reports that a button is greyed out, it is almost always because their role allows the action but nobody has assigned them a seat — and that is fixed by assigning a seat, not by changing their role.
Why Two Separate Ideas
Most teams have more people who need to look at reports than people who build them. A client contact who checks last month's numbers, an account manager reviewing a dashboard before a call, a founder glancing at spend — none of them touch a query.
Those people should be able to see the work without being able to change it. A role on its own does not quite express that: "Editor, but read-only for now" is a real thing to want when somebody joins, goes on leave, or is a client you would rather not have editing your dashboards. The seat is that switch, and it moves without touching anyone's role.
What Happens Without a Seat
A seatless member can do everything their role allows except change things. Concretely:
| They can | They cannot |
|---|---|
| Open the Hub and read every dashboard, client and report their role allows | Create or edit a dashboard, client, goal or theme |
| Open the Google Sheets add-on and read the queries and schedules in a sheet | Create, edit or delete a query or schedule, or refresh a sheet on demand |
| Open the Looker Studio popup and see the connections and query configs | Add a connection, enable an account, or create a query config |
| Keep an API key or MCP connection they already set up working | Use that key for anything a seat would be needed for in the interface |
| See how much of the plan is used, if their role includes it | Change the plan, buy seats, or cancel |
Scheduled refreshes are not affected by anybody's seat. They run on the team's plan with no person attached, so a sheet does not stop updating because the person who built it lost their seat.