Roles and permissions
The three roles, the eight permissions, and why an administrator of one measurement server cannot create a second one.
There are three roles and eight permissions. The distinction that explains everything: some permissions are answered on a measurement server, others on the account.
The three roles
Owner belongs to the account, and therefore to whoever pays. This role is not handed out.
Administrator does everything there is to do with a measurement server.
Reader looks on without changing anything — useful for someone who only wants to see the figures.
A role on the account and a role on a single measurement server count on the same scale, and the stronger of the two wins.
What each role may do
On a measurement server:
| Permission | Reader | Administrator | Owner |
|---|---|---|---|
| View traffic | yes | yes | yes |
| View usage | yes | yes | yes |
| Manage the measurement server | no | yes | yes |
| Manage its members | no | yes | yes |
On the account:
| Permission | Reader | Administrator | Owner |
|---|---|---|---|
| Create or delete a measurement server | no | yes | yes |
| Manage account members | no | yes | yes |
| Plan, price and invoices | no | no | yes |
| Delete the account | no | no | yes |
Why that split exists
Someone invited to a single measurement server has no role on the account. That means they cannot create a measurement server either — and that is not an arbitrary restriction.
Creating a measurement server costs money and hangs under a subscription. Someone with access to one server has no account to hang it under. If they could, an agency would be able to run up costs on its client’s account without the client seeing it.
It is the same arrangement that means you front nothing as an agency. See Working for clients.
A role that is not recognised
If the database holds a role this code does not know, it ranks below every real role — not above. A value that is not understood can therefore only ever grant less, never more.