Team and invitations
Workspaces isolate data. Every authenticated action checks membership and role before showing link content, analytics, exports, or billing.
Permission matrix
| Capability | Owner | Admin | Analyst | Member |
|---|---|---|---|---|
| Manage billing / Stripe portal | Yes | No | No | No |
| Create / edit link content | Yes | Yes | No | No |
| Delete links | Yes | No | No | No |
| Export analytics CSV | Yes | Yes | Yes | No |
| Invite / remove members | Yes | Yes | No | No |
Invitation flow
Owners and admins send invitations to an email address with a selected role among those allowed for invites. Recipients authenticate and accept a signed invitation link to join the workspace.
API tokens
Personal access tokens belong to a user but are scoped to a workspace ability. Governance for token issuance should mirror your internal access reviews. See API reference.