← All help articles
Account & workspace
Who is allowed to do what?
Roles separate how the site is built from what goes on it.
Permissions split in two: structure (content types, blocks, settings, tokens — how the site is built) and content (writing, editing, publishing — what goes on it). That split is what lets you hand a site to a client safely.

Owner — everything, including billing and team.
Developer — builds the structure; reads content.
Editor — writes, edits and publishes content.
Author — writes and edits drafts, but does not publish.
Viewer — read only.
These are starting points, not a fixed list: clone one and adjust it, or build a role from scratch — "Marketing manager", "Translator" — down to individual content types. See Creating a custom role, or invite someone new with the role already applied.