Team roles
What you can do to the account: people, Environments, billing.A Team always has at least one Owner. The last one cannot be demoted or removed, and cannot
leave — promote somebody else first. Livry enforces this on both the demotion path and the
departure path.
Environment roles
What you can do inside one Environment. Granted per Environment, per person.
What Admin adds over Editor, in practice: changing a Theme’s integrations, its serving mode and
signing keys, its allowlists, and the Environment’s own settings.
Creating an Environment grants you Admin on it. That is one of only four paths that write a
grant — the others are accepting an invitation, an Admin editing a member, and signup (which
creates no Environment, so writes no grant).
Worked combinations
That last row surprises people. It is correct.
Changing a role
A role change takes effect on the next request, not the next sign-in. There is no need to ask somebody to log out and back in. Team Admins and Owners manage this on the Team’s Members page.Through the API
The Public API enforces exactly the same checks through exactly the same code — a Team Admin with no grant gets a403 there too, and GET /environments lists only the
Environments the caller was granted.
Every Environment the API returns carries your role on it, so a client can tell whether a write
will be refused before attempting it.