Workspace roles make team access visible across AmICited. Owners, admins, editors, members, guests and maintainers are not a marketing hierarchy: each feature declares the actions it permits, especially where a write changes a source mapping, index or cost.
Permission is evaluated per resource; a role label alone is not a promise of the same access everywhere.
Role baseline
OwnerFull access
AdminFull access
EditorFull access
Member / Guest / MaintainerRead by default
Feature matrices can narrow this baseline, particularly for guest and maintainer access.
Default access is only the start
Workspace Role Access
The general baseline gives owners, admins and editors full actions while members, guests and maintainers read. But AmICited feature matrices are deliberately stricter: for example, domain management excludes guests and maintainers, while platform connections let editors read but reserve changes for owners and admins.
Do not assume Member can edit just because they can read a report.
Do not assume Maintainer equals Editor; access is feature-specific.
Guests are excluded from several AmICited surfaces even when another resource’s default permits reading.
Writes deserve explicit authority
Report and Source Permissions
Reporting often has a broader audience than configuration. Paid PPC reports are read-only to the roles allowed in; platform connections and source mappings have their own management boundary; Search Console actions are separately authorized. This avoids a reader receiving accidental authority to change an external system.
Examples
DomainsOwner / Admin / Editor manage
ConnectionsOwner / Admin manage
GSC writesOwner / Admin / Editor
PPC reportsRead-only roles
Google Search Console update actions and connection changes are intentionally different permission decisions.
Team operations
MembershipAdd / update / remove
OwnershipTransfer by owner
Old ownerBecomes admin
Plan gatesApply separately
Changing a role does not override subscription limits, SSO configuration eligibility or provider authorization.
Workspace administration
Workspace Membership Management
Owners and administrators can manage workspace membership; ownership transfer is restricted to the owner or a sudoer and changes the former owner to Administrator. Role permissions and plan limitations remain separate checks, so a high role does not automatically unlock an unavailable feature.
6workspace role labels, interpreted through the feature they are acting onSee Enterprise SSO
Give a team visibility without accidentally granting a write
Use resource-aware access so reports can be shared more broadly than external-source configuration.