SendOps uses a role-based access model with eight roles. Every person in your organization is assigned exactly one role, and that role determines what they can see and do across the dashboard. The sidebar navigation automatically adapts to show only the sections relevant to each role.

## Roles overview

| Capability | Owner | Org Admin | Infra Admin | Developer | Marketer | Financial | Support | Viewer |
|---|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|
| **Organization Settings** | ✓ | ✓ | — | — | — | — | — | — |
| **Team Management** | ✓ | ✓ | — | — | — | — | — | — |
| **Billing — Plan & Usage** | ✓ | Read | — | — | — | ✓ | — | — |
| **Billing — Invoices & Payments** | ✓ | — | — | — | — | ✓ | — | — |
| **Billing — SES Cost Estimates** | ✓ | — | — | — | — | ✓ | — | — |
| **AWS Connections** | ✓ | ✓ | ✓ | — | — | — | — | — |
| **Domains & Tracking Domains** | ✓ | ✓ | ✓ | Read | Read | — | Read | Read |
| **Channels** | ✓ | ✓ | ✓ | ✓ | Read | — | Read | Read |
| **Templates** | ✓ | ✓ | Read | ✓ | Read | — | Read | Read |
| **SES Template Export** | ✓ | ✓ | ✓ | ✓ | View | — | — | View |
| **GitHub Integration** | ✓ | ✓ | — | ✓ | — | — | — | — |
| **Reports & Analytics** | ✓ | ✓ | Read | ✓ | ✓ | Read | ✓ | Read |
| **Recipient Search** | ✓ | ✓ | ✓ | ✓ | — | — | ✓ | — |
| **Suppression Lists** | ✓ | ✓ | — | Read | ✓ | — | ✓ | Read |
| **Notifications** | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | Read | Read |
| **Audit Log** | ✓ | ✓ | Read | Read | Read | Read | Read | Read |
| **Setup Guide** | ✓ | ✓ | ✓ | Read | Read | — | — | Read |
| **Contacts, Lists, Segments & Attributes** | ✓ | ✓ | Read | ✓ | ✓ | — | Read | Read |
| **Drip Workflows** | ✓ | ✓ | Read | ✓ | ✓ | — | Read | Read |
| **Broadcasts** | ✓ | ✓ | Read | ✓ | ✓ | — | Read | Read |
| **Tags & Folders** | ✓ | ✓ | Read | ✓ | ✓ | — | Read | Read |
| **Image Assets** | ✓ | ✓ | Read | ✓ | ✓ | — | — | Read |
| **API Keys** | ✓ | ✓ | — | — | — | — | — | — |

In the table above, **✓** means the role can both view and make changes in that area, **Read** means view-only access, and **—** means no access.

The audience and automation areas — **Contacts, Lists, Segments, Attributes, Drip Workflows, Broadcasts, Tags & Folders, and Image Assets** — follow a consistent pattern: they can be *changed* by the Owner, Org Admin, Developer, and Marketer roles, and *viewed* by everyone else who has operational or read access. Customer Support can view these areas for troubleshooting (but not the image asset library); the Financial role, which is scoped to billing only, cannot see them at all. **API Keys** are more restricted — only the Owner and Org Admin can view or manage them.


  Every organization has exactly one Owner. You can transfer ownership to another team member directly from Workspace Settings — see [Transferring ownership](#transferring-ownership) below.


## Role details

### Owner

The Owner has full, unrestricted access to the organization. In addition to everything an Org Admin can do, the Owner can:

- **Transfer ownership** — hand the Owner role to another team member directly from [Workspace Settings](/team/account-settings). See [Transferring ownership](#transferring-ownership) below.
- **Delete the organization** — permanently remove the organization and all of its data.

The person who creates the organization is automatically assigned the Owner role. There can only be one Owner per organization.

### Org Admin

Org Admins have full access to the organization except for deletion, ownership transfer, and detailed billing management. They can:

- Add, remove, and change roles for team members.
- View the current plan and usage limits (read-only — invoices, payment methods, and plan changes are managed by the Owner or Financial role).
- Manage all infrastructure settings including AWS connections, domains, channels, and tracking domains.
- Create and edit templates.
- Manage the full audience and automation layer — contacts, lists, segments, attributes, drip workflows, broadcasts, and tags & folders.
- Create and manage API keys for the SendOps public API.
- Configure notification rules and webhooks.
- View the [audit log](/team/audit-log).

### Infra Admin

Infra Admins focus on infrastructure and connectivity. They can:

- Manage AWS connections, domains, and tracking domains.
- Manage channels.
- Access the setup guide.
- View templates, reports, and the [audit log](/team/audit-log) (read-only).
- View the audience and automation layer — contacts, lists, segments, attributes, drip workflows, broadcasts, tags & folders, and image assets (read-only).
- Manage notification preferences.

Infra Admins cannot manage team members, billing, template editing, GitHub connections, API keys, or the audience and automation data. They can export existing SES templates — see [Importing from SES](/templates/importing-from-ses).

### Developer

Developers focus on templates and day-to-day email operations. They can:

- Create and edit templates.
- Manage GitHub connections and template syncs.
- Manage channels.
- Manage the full audience and automation layer — contacts, lists, segments, attributes, drip workflows, broadcasts, tags & folders, and image asset organization.
- Manage notification preferences.
- View domains, tracking domains, reports, suppression lists, and the [audit log](/team/audit-log) (read-only).

Developers cannot manage team members, billing, AWS connections, API keys, or organization settings.

### Marketer

Marketers focus on the audience, campaigns, analytics, and reporting. They can:

- View and export reports and analytics.
- Manage the full audience and automation layer — contacts, lists, segments, attributes, drip workflows, broadcasts, tags & folders, and image asset organization.
- Manage suppression lists.
- Manage notification preferences.
- View templates, channels, domains, and the [audit log](/team/audit-log) (read-only).

Marketers cannot modify infrastructure settings, edit templates, manage API keys, or access AWS or GitHub connections.

### Financial

The Financial role is designed for finance and accounting teams who need access to billing, invoices, and cost data without seeing operational product features. Financial users can:

- View and manage invoices, payment methods, and billing settings.
- Download invoice PDFs and export billing history.
- View the current plan and usage limits.
- View estimated SES costs and export cost data.
- View reports and analytics (read-only, for cost context).
- View the [audit log](/team/audit-log) (read-only).
- Manage their own notification preferences.

Financial users cannot access templates, channels, domains, AWS connections, GitHub integrations, suppression lists, the audience and automation layer (contacts, lists, segments, workflows, broadcasts), API keys, or organization settings. Their sidebar shows only the sections relevant to billing and finance.

### Customer Support

The Customer Support role is designed for people who troubleshoot email delivery — looking up whether a specific email was delivered, bounced, or complained, searching by recipient, and managing suppression lists. Customer Support users can:

- View and export reports and analytics.
- Search by recipient email address to trace individual deliveries.
- View and manage suppression lists — remove erroneously suppressed addresses so recipients can receive email again.
- View templates, channels, and tracking domains (read-only, for delivery context).
- View the audience and automation layer — contacts, lists, segments, attributes, drip workflows, broadcasts, and tags & folders (read-only, for lookup and triage).
- View the [audit log](/team/audit-log) (read-only).
- Manage their own notification preferences.

Customer Support users cannot modify infrastructure settings, edit templates, change the audience or automation data, access AWS or GitHub connections, manage billing or API keys, invite team members, or change organization settings.

### Viewer

Viewers have read-only access across the dashboard. They can view reports, templates, channels, domains, suppression lists, the audience and automation layer (contacts, lists, segments, attributes, drip workflows, broadcasts, tags & folders, and image assets), the [audit log](/team/audit-log), and notification settings — but cannot modify anything.

## Inviting a team member


  <Step title="Open the Team settings">
    In the SendOps dashboard, navigate to **System → Team**. You will see a list of current members and their roles.
  </Step>
  <Step title="Click Invite Member">
    Click the **Invite Member** button at the top of the member list.
  </Step>
  <Step title="Enter their email address">
    Type the email address of the person you want to invite. They do not need a SendOps account yet — they will be prompted to create one (or sign in with Google or GitHub) when they accept the invitation.
  </Step>
  <Step title="Choose a role">
    Select a role from the dropdown — **Org Admin**, **Infra Admin**, **Developer**, **Marketer**, **Financial**, **Customer Support**, or **Viewer**. You can change their role later from the same Team settings page.
  </Step>
  <Step title="Send the invitation">
    Click **Send Invite**. The invitee receives an email with a link to join your organization. Pending invitations appear in the member list with a "Pending" badge until accepted.
  </Step>



  The Free plan supports a single user. To invite additional team members, upgrade to the **Team** or **Business** plan. Visit [sendops.dev/pricing](https://sendops.dev/pricing) for details.


## Accepting an invitation

There are two ways to accept an invitation to join an organization.

### From the email link

When someone invites you, you receive an email showing the organization name, your assigned role, and who invited you. Click **Accept invitation** in the email to be taken directly to SendOps.

- If you are already signed in, the invitation is accepted automatically and you are redirected to the organization's dashboard.
- If you are not signed in, you will be prompted to sign in (or create an account) first. After signing in the invitation is processed.

### From the dashboard

If you are already signed in to SendOps, pending invitations also appear as a banner at the top of your dashboard. The banner shows the organization name and role, with **Accept** and **Decline** buttons. If you have multiple pending invitations, the banner links to your **Profile** page where you can review and respond to each one.

You can also view all pending invitations at any time from your **Profile** page. Each invitation shows the organization name, the role you have been offered, and when the invitation expires. From there you can accept or decline each invitation individually.


  You can belong to more than one organization. After accepting an invitation, SendOps switches to the new organization automatically. Use the organization switcher to move between organizations. Each organization has its own role assignment, so you may be an Admin in one organization and a Viewer in another.



  Invitations expire after 7 days. If an invitation has expired, the acceptance page will let you know — ask the organization Owner or Admin to send a new one from **System → Team**.


## Changing a member's role

Owners and Org Admins can change any member's role from **System → Team**. Click the role badge next to a member's name, select the new role, and confirm. Role changes take effect immediately.

## Removing a member

To remove a member, click the menu icon next to their name in the Team settings and select **Remove**. The member immediately loses access to the organization. Their past actions remain recorded in the [audit log](/team/audit-log).


  You cannot remove a member who has a pending ownership transfer. Cancel the transfer first from **Workspace**, then remove the member.


## Transferring ownership

The Owner can transfer their role to any other active member of the organization. After the transfer, the former Owner is demoted to **Org Admin** and retains full access to the organization except for ownership transfer and workspace deletion.

### Initiating a transfer


  <Step title="Open Workspace Settings">
    Navigate to **Workspace** and scroll to the **Danger Zone** section.
  </Step>
  <Step title="Click Transfer Ownership">
    Click **Transfer Ownership** to open the transfer modal.
  </Step>
  <Step title="Select a team member">
    Choose the member you want to transfer ownership to. The member must have a verified email address.
  </Step>
  <Step title="Confirm the transfer">
    Review the details and confirm. Both you and the target member will receive an email notification. The target has **72 hours** to accept the transfer.
  </Step>


While a transfer is pending, a banner appears on the **Team** page showing the target member's name, the expiry time, and a **Cancel Transfer** button. You can cancel the transfer at any time before it is accepted or expires.

### Accepting a transfer

There are two ways the target member can accept an ownership transfer:

**From the email link** — the invitation email contains an **Accept ownership** button that links directly to SendOps. If the target is not signed in, they will be prompted to sign in first.

**From the dashboard** — a banner appears at the top of the target member's dashboard showing who initiated the transfer, with an **Accept** button.


  If the organization enforces two-factor authentication, the target member must have MFA set up on their account before they can accept the transfer. See [Multi-factor authentication](/team/account-settings#multi-factor-authentication) for setup instructions.


### What happens when a transfer is accepted

- The target member becomes the new **Owner**.
- The former Owner is changed to the **Org Admin** role.
- Both users are signed out of all sessions and must sign in again.
- Both users receive a confirmation email.
- The new Owner sees a banner prompting them to review their [billing contact details](/billing/plans-and-usage) to ensure invoices and receipts go to the correct address.

All ownership transfer actions — initiated, accepted, cancelled, and expired — are recorded in the [audit log](/team/audit-log).

### Cancellation and expiry

- The Owner can **cancel** a pending transfer at any time. The target member receives a cancellation email.
- If the target does not accept within **72 hours**, the transfer **expires automatically**. Both parties receive an expiry notification.
- After a cancellation or expiry, you can immediately initiate a new transfer to the same or a different member.

## What's next?

- Review the [Audit Log](/team/audit-log) to see a record of every change made in your organization.
- Update your profile and security settings in [Settings & Profile](/team/account-settings).