Roles and permissions
Understand Servor team roles — owner, admin, member and viewer — and see exactly what each role can do with a clear permissions matrix.
Every person on a Servor team has a role that decides what they can see and do. This page explains the four roles — owner, admin, member and viewer — and gives you a permissions matrix so you can pick the right one when you invite a teammate or change someone's role.
The four roles at a glance
Roles are ranked from most to least access:
Full control of everything, including billing, the plan, and deleting or transferring the team.
Manages infrastructure, team settings, billing and API tokens, and can invite people.
Day-to-day operator: runs commands, uses the terminal and AI copilot, edits things and reports incidents — but can't create servers, monitors or status pages.
Read-only everywhere. Sees monitors, status pages, command history and incidents, but can't change anything.
What each role can do
| Capability | Viewer | Member | Admin | Owner |
|---|---|---|---|---|
| View monitors, status pages, incidents, command history | ✓ | ✓ | ✓ | ✓ |
| Run commands, use the web terminal, use the AI copilot | — | ✓ | ✓ | ✓ |
| Edit existing servers, monitors and status pages | — | ✓ | ✓ | ✓ |
| Report and update incidents | — | ✓ | ✓ | ✓ |
| Create servers, monitors and status pages | — | — | ✓ | ✓ |
| Manage team settings and invite people | — | — | ✓ | ✓ |
| Manage billing, plan and seats | — | — | ✓ | ✓ |
| Create and revoke API tokens | — | — | ✓ | ✓ |
| Delete or transfer the team | — | — | — | ✓ |
Members can edit but not create infrastructure
A member can operate everything the team already has — run commands, open the web terminal, tweak an existing monitor, post an incident update — but adding a brand-new server, monitor or status page is an admin action.
Which role should I give someone?
- Give viewer to stakeholders, clients or on-call watchers who only need to see status and history. Viewers never need to unlock a vault and don't take up encrypted access.
- Give member to engineers who operate the fleet day to day but shouldn't be spinning up new infrastructure or touching billing.
- Give admin to the people who run the account — they can add infrastructure, invite teammates, manage the plan and create API tokens.
- Keep owner for the account holder. There should normally be one; transferring ownership is an owner-only action.
Start low, promote later
Invite people at the lowest role that lets them do their job, then promote them if they need more. It's easier to grant access than to walk it back. Manage roles in Servor
Roles and encrypted access
Roles decide permissions, but running commands also requires encrypted access, which is granted the first time a member, admin or owner joins. If a new teammate is stuck on the "waiting for a teammate to come online" screen, that's about encrypted access, not their role — see Invite teammates for the one-step fix.