# Roles and permissions

*In development* · Last updated 2026-10-08

> This document describes the platform foundation under development. Details may change before launch.

The four workspace roles, exactly what each one may do, and the rules that apply to administrative actions.

Every member of a workspace has one role. The role decides what they may do; their locations decide where.

- **Owner**: Full control of the workspace, including billing, members and deletion.
- **Manager**: Manages people, locations and day-to-day settings. Cannot change billing or delete the workspace.
- **Staff**: Works within assigned locations. Can upload files and use the assistant.
- **Read-only**: Can view assigned locations. Cannot change anything.

## Permission table

The table below is generated from Landmate's shared permission matrix when this site is built, so it always matches what the platform enforces.

| Permission | Applies to | Owner | Manager | Staff | Read-only |
| --- | --- | :---: | :---: | :---: | :---: |
| View the workspace | workspace | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Change workspace details | workspace | ✓ Yes | ✓ Yes | — No | — No |
| Delete the workspace (fresh sign-in) | workspace | ✓ Yes | — No | — No | — No |
| Export the workspace data (fresh sign-in) | workspace | ✓ Yes | — No | — No | — No |
| See members | workspace | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Invite members | workspace | ✓ Yes | ✓ Yes | — No | — No |
| Change a member's role (fresh sign-in) | workspace | ✓ Yes | ✓ Yes | — No | — No |
| Remove members (fresh sign-in) | workspace | ✓ Yes | ✓ Yes | — No | — No |
| View locations | location | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Create and manage locations | workspace | ✓ Yes | ✓ Yes | — No | — No |
| View files | location | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Upload files | location | ✓ Yes | ✓ Yes | ✓ Yes | — No |
| Delete files | location | ✓ Yes | ✓ Yes | — No | — No |
| View billing | workspace | ✓ Yes | ✓ Yes | — No | — No |
| Manage billing (fresh sign-in) | workspace | ✓ Yes | — No | — No | — No |
| Use the AI assistant | location | ✓ Yes | ✓ Yes | ✓ Yes | — No |
| Configure the AI assistant | workspace | ✓ Yes | — No | — No | — No |
| Read the audit log | workspace | ✓ Yes | ✓ Yes | — No | — No |
| Read their own notifications | own account | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| Manage API keys (fresh sign-in) | workspace | ✓ Yes | — No | — No | — No |
| Manage integrations (fresh sign-in) | workspace | ✓ Yes | — No | — No | — No |
| Manage workspace settings | workspace | ✓ Yes | ✓ Yes | — No | — No |

**Location scope.** Permissions marked "location" are also limited to the member's locations. See [Workspaces and locations](https://www.landmate.app/docs/workspaces-and-locations).

## Rules for administrative actions

- **Fresh sign-in.** Sensitive actions — deleting or exporting a workspace, changing a member's role, removing a member, managing billing, API keys or integrations — ask you to confirm your password or second factor if you have not done so in the last 10 minutes.
- **Managers and rank.** A Manager may invite, change or remove only Staff and Read-only members, and may not make anyone a Manager or Owner.
- **Changes apply immediately.** A role change, removal or deactivation takes effect on the member's next request. Roles are not cached in the session.
- **Removal revokes access.** Removing a member also revokes the API keys and app authorizations that member created for the workspace.

## Reserved permissions

Some permissions exist in the matrix only so that the roles stay stable when the planned features ship. They are **denied to every role** until the feature exists:

- View properties
- Manage properties
- Manage units
- Manage residents and contacts
- Manage leases
- Manage maintenance
- Manage documents
- View reports
- Collect rent

## Landmate support access

Landmate support staff are not workspace members. If support ever needs to look at a workspace on a user's behalf, the platform is designed so that:

- access needs a written reason and ends after at most 60 minutes;
- it is read-only by default, and writing needs a separate, audited step;
- it never exceeds the access of the user being helped, and ends if that user's membership ends;
- a banner that cannot be dismissed is shown on every screen during the session;
- billing, API keys, integrations, workspace deletion or export, password and second-factor changes, and account deletion are always blocked;
- the start, every change and the end are written to the audit log, which the workspace Owner can read.
