Roles & permissions
The roles people and API keys can hold, what each can do, and how membership works when you belong to more than one account.
4 min read
On this page
Users belong to an organization, with one role each. Roles are set per organization, so being an owner of your own account says nothing about your role in a client’s.
The roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing, deleting the account, and changing other members’ roles. Every organization has at least one. |
| Admin | Everything operational — stores, reviews, loyalty, FAQs, galleries, widgets, email, API keys — but not billing or account deletion. |
| Member | Day-to-day work: moderating reviews, answering FAQs, curating galleries. Not connection settings or keys. |
Ownership cannot be given up by leaving. If you are the only owner, promote someone before you remove yourself.
API keys have roles too
An API key is not a person, but it carries a role the same way, chosen when you create it. Keys can hold one more role than people can:
| Role | Can do |
|---|---|
| Viewer | API keys only — the default for a new key. Blocked from changing the catalogue, orders, loyalty balances, billing, the team and other keys. Not blocked from everything else: on its own it can still act on reviews, FAQs and galleries. For a key that must not write anything, also set its Access to Read-only when you create it. |
The role is the coarse limit and the key’s scopes narrow it further; a request has to be allowed by both. Pick the lowest role that does the job, then scope it to the resources the integration actually touches.
Belonging to several organizations
Your email address identifies you within an organization, not across all of Evident. The same address can be an owner of your own account and a member of three client accounts, with a different role in each.
Practical consequences:
- Signing in shows an account picker when your address matches more than one organization. Which one you land in is a choice, never an inference — Evident will not guess an organization from an email address.
- An invitation to a second organization is a new membership, not a transfer. Accepting does not affect the first.
- API keys belong to one organization and one store, never to you personally.
Inviting people
Settings → Team — invite by email address and pick a role. The invitation email comes from Clerk, our identity provider.
If an invite does not arrive, check Gmail’s Promotions tab before assuming it was not sent; that is where these tend to land.
Store-scoped access
Users who reach Evident from inside a BigCommerce or Shopify control panel, but who have no Evident user record, are signed in scoped to that store. They can work with that store’s data and nothing else — no organization settings, no billing, no other stores. This is deliberate: a staff account on a merchant’s platform should not inherit access to the merchant’s whole Evident organization by virtue of clicking an app icon.
To give someone full access, invite them properly under Settings → Team.
Partners and agencies
Agency and partner accounts have their own entitlement layer on top of roles, governing client handoffs, commissions and agency-managed billing. If you are running Evident across a portfolio, start with Managing client stores.
Auditing who did what
Two logs, and they answer different questions:
- Activity — what changed in the product: reviews moderated, settings edited, imports run.
- Security audit — who signed in, whose role changed, when a key was created or revoked.
See Activity & audit log.
Something missing or out of date? Email support@evidentugc.com — docs corrections go straight to the team that builds the feature.