Checking session
Back to Help
Back to workspace
Concept reference

Account members and permissions

How account membership, invitations, roles, and scoped permissions work together.

Account membership controls who can access account-owned work. Permissions can be scoped to the account, project, book, or manuscript depending on the role being assigned.

  • Members shows who can access the account and whether they have pending or active status.
  • Invitations let an owner or authorized member invite someone by contact, pen name, or email address.
  • Resource selects the scope for an invitation or role assignment.
  • Role selects the capabilities granted at that scope.
  • Inherited means no direct role is assigned at the selected scope, so access comes from a higher scope.

Role levels build on each other:

  • Owner has full, irrevocable access to the account and everything inside it. Ownership is not assigned from the permissions sheet.
  • Manager can manage resources in the selected scope, including destructive actions where the scope allows them. Account managers can also manage invitations.
  • Editor can create and update content in the selected scope, but cannot manage membership or perform manager-only cleanup.
  • Viewer can read the selected scope, add callouts, and participate in chat, but cannot edit manuscript or project structure.

Removing a member or revoking an invitation affects access immediately. Review the selected account and resource before confirming destructive membership changes. The entry-level account has 2 total member seats, including the owner. Each pending, unexpired invitation reserves a seat. If an invitation was sent under a higher quota and the quota later drops, the invitation remains visible but cannot be accepted until sufficient capacity is restored; the owner can revoke it to release the reservation.

The Members dialog also shows account capacity for logical assets, unique physical asset storage, monthly render jobs, active renders, and uncached local-TTS minutes. Shared storage objects are counted once even when multiple logical assets reference them. Deleting an asset releases customer-visible capacity immediately; backup remnants follow the retention schedule. Monthly render and local-TTS usage resets on UTC calendar-month boundaries. Cache hits and external provider TTS do not consume local-TTS minutes.