My accountAccess model guide
Demo identities · no real permissions changed
WORKSPACE & ACCESS MODEL

The right access. At every level.

The platform owner and the customer workspace owner are different responsibilities.

01 · PLATFORM

Super Admin

The AppDuz owner. Oversees all customer workspaces, apps, availability, and platform policies.

Platform console
02 · CUSTOMER

Workspace owner

The customer who owns a workspace. Manages billing, assigns administrators, and controls their own apps.

Workspace console
03 · TEAM

Invited members

Admins, developers, editors, and viewers receive only the permissions and app assignments they need.

Members & access

Clear boundaries by design

No cross-customer accessMembership in one workspace never grants membership in another.

App-level assignmentsA developer or editor can be invited to just one app.

Ownership stays explicitWorkspace admins cannot appoint owners or create Super Admins.

Workspace permission matrix

Owners and admins cover the workspace. Other roles are limited to assigned apps.

Default role model
CapabilityOwnerAdminDeveloperEditorViewer
View apps & previewsOpen apps assigned to the member.AssignedAssignedAssigned
Edit design & contentChange the app’s presentation and content.AssignedAssigned
Prepare app buildsConfigure and queue builds for assigned apps.Assigned
Approve publishingApprove releases to distribution channels.
Configure integrationsManage approved connections without exposing stored secrets.Assigned
Manage team accessInvite members and update permitted roles.
Manage billing & planControl the customer’s subscription and invoices.
Manage workspaceUpdate shared workspace preferences.
“Assigned” means selected apps only. Admins can manage Developer, Editor, and Viewer memberships—not ownership or peer admins.
Frontend role-preview prototypeIdentity switching, permissions, invitations, and audit events use local sample data. Production must authenticate users and enforce tenant and resource permissions on the server, not rely on this UI.