Two Minute Reports Logo
Roles & Permissions

Seats

A seat is permission to change things in one team. What a seatless member can still do on every surface, what is refused, and why scheduled refreshes never stop.

A seat is permission to change things in one team. Every current plan includes unlimited users, so a seat is not something you buy — it is a switch you control, per person.

Assigning a role and assigning a seat are two separate actions. A member with a role and no seat can see everything that role allows and change none of it.

The Four Rules

  1. No seat means read-only in that team. Every permission that requires a seat is withheld. Every permission that does not still works.
  2. Seats are per team, per request. The same login, the same API key and the same MCP connection answer differently depending on which team is involved. If you belong to two teams, you can have a seat in one and not the other — and that is a normal setup, not a broken account.
  3. The Owner is the exception. The account owner can change the plan and assign seats with or without a seat of their own. Otherwise a team that used its last seat could never assign another.
  4. Removing a seat is not removing a person. They keep every read their role allows until you actually remove them from the team.

Seated vs Seatless, Surface by Surface

The Hub

With a seatWithout a seat
Create and edit dashboards, widgets, pages and themesRead every dashboard the role allows; every editing control is disabled with the reason
Create, edit and delete clients, goals, custom fields and initiativesSee all of them, change none
Add connections and enable connected accountsSee which platforms are connected and whether each is still authorised
Share a dashboard publicly and send briefingsOpen a dashboard someone else shared
Invite members, set roles and assign seats, if the role allows itSee the member list, if the role allows it

Google Sheets Add-On

With a seatWithout a seat
Create, edit, copy and delete queriesOpen the sidebar and read every query in the sheet
Create, edit and delete schedulesSee the schedules and when each last ran
Refresh a sheet on demand, and use Run all queries— refused, because each run calls the ad platform
Add connections and enable accountsSee connections and their accounts
Copy a template or duplicate a reportBrowse the template gallery

A seatless member sees a banner at the top of the sidebar explaining the situation, so they are not left guessing why a button is grey.

Looker Studio Popup

With a seatWithout a seat
Create, rename, re-authenticate and delete connectionsSee the connections and their status
Enable and disable connected accountsSee which accounts are enabled
Create, edit and delete query configsSee the query configs

API and MCP

This is the part worth reading twice.

A key carries the permissions of the person who created it, and its scopes can only narrow that — never widen it. A key made by a Viewer cannot write, no matter what scopes it is given. A key made by an Editor who later loses their seat stops being able to write, without the key changing at all.

API and MCP access itself does not require a seat. If someone set up an integration and later lost their seat, the connection keeps working and its read calls keep answering. What stops is the writes.

One person, two teams. Seats are per team, so the same key behaves differently depending on which team a request names. Somebody with a seat in Team A and none in Team B will get writes accepted for A and refused for B — with the same key, in the same session.This looks exactly like a broken key, and it is not. The refusal names the team for that reason: read the team name in the error before assuming the credential is at fault. Around 1,080 people belong to more than one team, so this is a real situation rather than a hypothetical one.

Scheduled Refreshes Never Stop

A Google Sheets schedule keeps running whoever created it — even if that person has lost their seat or left the team entirely.

The only things checked on the running path are that the team's plan is active and its limits are not exceeded. Seats gate creating or editing a schedule, not the refresh itself.

This is deliberate. A scheduled refresh has no person in it: it is the team's plan doing work on the team's behalf. Making it depend on somebody's current seat would mean a client's Monday-morning report silently stopping because an account manager changed jobs.

So un-seating someone is safe for the reports they already built. What they lose is the ability to build new ones or change existing ones.

Running Out of Seats

Not something current plans do — they include unlimited users, so there is no limit to reach.

Some older plans bought before the current lineup carry a fixed seat count. On one of those, if every seat is taken you have two ways out:

  1. Un-assign a seat from somebody who does not currently need one. Their reports keep running and they keep every read.
  2. Move to a current plan, which has no seat limit. Only someone with permission to change the plan — the Owner or an Admin — can do that.

A Deputy Admin can assign seats but cannot change the plan, so on an older plan that is the point at which they need an Admin.

Common Questions

Does a seatless member count towards my plan? No. Every current plan includes unlimited users, seated or not.

Can I give a client a seat? Yes, and sometimes it is right — a client who maintains their own dashboards needs one. But most clients only read, and that needs no seat.

Do I get a seat back immediately when I un-assign one? Yes. Seat counts are live.

Does the Owner use a seat? The Owner can change the plan and assign seats without one. For everything else, the Owner is like anybody else and needs a seat to make changes.

Copyright © 2026