Skip to Content
Account ManagementRoles and Permissions
How-to guideAccount managementAvailable

Roles and Permissions

Understand team membership, Owner and Member roles, seeded workspace permissions, invitations, and primary-owner-only actions.

Last reviewed July 13, 2026

Vendo is team-first: product data belongs to a team workspace, and access is checked against that workspace membership. Open Workspace Settings → Members to review members, pending invitations, and roles.

Roles

RoleIntended use
OwnerWorkspace administration, billing, role changes, API-key administration, and approval-sensitive operations
MemberDay-to-day workspace use and the non-administrative permissions granted to the seeded Member role

The primary owner is a specific Owner recorded on the account. Some account-level actions, such as ownership transfer or deleting the workspace, require the primary owner and may require a one-time password.

Seeded permissions

Vendo checks named permissions for administrative and approval-sensitive operations. The current seeded role model includes:

Permission areaOwnerMember
Manage rolesYesNo
Manage billingYesNo
Manage workspace settingsYesYes
Manage membersYesNo
Manage invitationsYesYes
Read/write/administer API keysYesNo
Edit commerce operationsYesYes
Approve commerce operationsYesNo

Feature routes and data tables also enforce team membership, row-level security, feature availability, and resource-specific checks. The table above is not a promise that every route maps only to one named permission.

Invite a member

  1. Open Workspace Settings → Members.
  2. Select Invite Member if your role exposes the action.
  3. Enter the email address and role.
  4. Send the invitation.
  5. Track or revoke it under Pending Invitations.

Change or remove a member

Members with roles.manage can change roles when the target role is below their own hierarchy. Member removal is also constrained by role hierarchy and primary-owner rules.

Before removing access:

  1. Confirm the correct workspace and person.
  2. Reassign any operational ownership that depends on the user.
  3. Rotate credentials or provider access the person controlled.
  4. Remove or update their membership.
  5. Review API keys and audit activity after the change.

API keys and external tools

API keys are account-scoped credentials with their own scopes and limits. Do not assume an API key safely inherits every property of the creator’s interactive session. Create the narrowest key required, store it as a secret, and revoke it when the integration is retired.

MCP OAuth uses the selected team account and approved mcp:read or mcp:write scope. Tool availability is still constrained by the connected account and server-side authorization.

Troubleshooting

SymptomCheck
Invite button is missinginvites.manage, workspace member limit, and active workspace
Role cannot be changedroles.manage, role hierarchy, and primary-owner status
Member cannot open dataMembership, active team workspace, RLS, and feature availability
API key action is unavailableAPI-key permission and whether an Owner must perform it
Need help?

Include your workspace, integration or job ID, and the first error message when you contact support.

support@vendodata.com
Last updated on