Guide
Team Roles and Permissions
Developer Team Accounts now expose fixed default roles backed by a canonical permission registry and platform middleware.
SoundSync
Role matrix
Sensitive financial and credential permissions are separate.
| Role | Allows | Sensitive restrictions |
|---|---|---|
| Owner | All developer-team permissions | Owner-only for owner role assignment, last-owner protection, tax/payout/highest-risk operations |
| Administrator | Broad operations, products, customers, marketing, credentials, team administration | Cannot assign owner unless owner path is used; tax and owner protections remain restricted |
| Product Manager | Assigned products, files, storefront, reviews, product analytics | No billing, payouts, tax, credential rotation, or team administration |
| Customer Support | Assigned-product customers, orders, entitlements, serials, support records | No billing, payouts, tax, marketing, or credentials |
| Marketing | Campaigns, promotions, storefront content, brand/review content where product scope allows | No billing, payouts, tax, credentials, or team administration |
| Analyst | Read-only analytics, orders, product performance, non-sensitive reporting | No mutations, billing setup, payouts, tax, credentials, or team administration |
| Billing | Billing, statements, settlements, payouts, refunds/disputes visibility, tax visibility | No product editing, marketing sends, credentials, or team administration |
| Developer / Engineer | Product integration surfaces, webhooks, API keys, product credentials, delivery/package settings | No payouts, tax, billing management, customer support mutations, or team administration |
