Roles and permissions
The five team roles — Owner, Admin, Editor, Writer, Viewer — and exactly what each one can do.
Roles and permissions
EarlyForge uses role-based access control with five roles. Every team member is assigned exactly one role, and that role decides what they can see and do across your organization.
The five roles at a glance
- Owner — everything, including billing
- Admin — manage the whole organization except billing
- Editor — full content access: create, edit, and publish articles, briefs, and trends
- Writer — work on their own articles and their own alerts
- Viewer — read-only access
Permission matrix
| Permission | Owner | Admin | Editor | Writer | Viewer |
|---|---|---|---|---|---|
| View articles | ✓ | ✓ | ✓ | ✓ | ✓ |
| View trends | ✓ | ✓ | ✓ | ✓ | ✓ |
| Follow trends | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create articles | ✓ | ✓ | ✓ | ✓ | ✗ |
| Edit own articles | ✓ | ✓ | ✓ | ✓ | ✗ |
| Edit all articles | ✓ | ✓ | ✓ | ✗ | ✗ |
| Hide own draft from team | ✓ | ✓ | ✓ | ✓ | ✗ |
| See hidden drafts of others | ✓ | ✓ | ✗ | ✗ | ✗ |
| Publish articles | ✓ | ✓ | ✓ | ✗ | ✗ |
| Manage briefs | ✓ | ✓ | ✓ | ✗ | ✗ |
| Manage own alerts | ✓ | ✓ | ✓ | ✓ | ✗ |
| Manage all alerts | ✓ | ✓ | ✓ | ✗ | ✗ |
| Manage team | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage sites | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage billing | ✓ | ✗ | ✗ | ✗ | ✗ |
| Delete organization | ✓ | ✗ | ✗ | ✗ | ✗ |
Role descriptions
Owner
Full control over the entire organization, including billing, subscription management, and deleting the organization. There is exactly one Owner — the person who created the account. Ownership can be transferred to another Admin from the organization settings.
Admin
Full operational control over everything except billing. Admins can invite, suspend, and remove members, create and configure sites, and manage all content. This is the right role for a managing editor or operations lead who shouldn't see payment details.
Editor
Full content access. Editors can create, edit, and publish articles across every site, manage briefs, manage alerts, and work with trends. Editors can't manage team membership or site-level settings.
Writer
Works on their own content. Writers can create and edit their own articles and use the AI editor, and they can set up their own alerts. They can't publish, edit other people's articles, or manage briefs. This role suits contributors who submit drafts for editorial review.
Viewer
Read-only access. Viewers can browse articles, explore trends, follow trends, and view reports, but can't create or change anything.
Viewers are free and unlimited — on every plan
Viewers never consume a paid seat. Invite your clients to follow the content you produce for them, bring executives and stakeholders into the dashboards, or add reviewers who only need visibility — as many as you want, at no cost. Only Owner, Admin, Editor and Writer roles count toward your plan's seats.
Assign Editor to most of your team. It gives full content access — creating, editing, and publishing — without admin responsibilities like managing membership or site configuration.
Which roles your plan unlocks
The set of roles you can assign depends on your plan:
| Plan | Roles available |
|---|---|
| Free | — (solo) |
| Starter | — (solo) |
| Pro | 3 roles |
| Scale | 5 roles |
| Enterprise | Custom |
Free and Starter are single-seat plans, so role assignment doesn't apply. Pro unlocks three roles for a small team. Scale unlocks all five. Enterprise adds custom role configurations on top. See Plans to compare.
Changing roles
Only Owner and Admin can change another member's role:
- Go to Settings → Team.
- Select the member whose role you want to change.
- Pick the new role from the dropdown and click Save.
Role changes take effect immediately.
An Owner can't demote themselves unless they first transfer ownership to another Admin. This prevents accidental lockout from billing and organization management.
Sign-in and security
All roles use the same sign-in options:
- Google or Apple — one-click sign-in
- Email — email and password with verification
- Two-factor authentication (2FA) — optional, available on every plan, configured per user from profile settings
Enterprise organizations can additionally require single sign-on through their own identity provider.
What's next?
- Manage your team — invite members, suspend access, and review the activity log
- Real-time collaboration — how roles map to editing and read-only access
- SSO & SCIM — single sign-on and directory sync for Enterprise