Skip to main content
Livry has two independent planes. Everybody holds exactly one Team role, and zero or more Environment grants.
A Team role grants no access inside an Environment.A Team Admin can create and delete Environments and still be unable to read a Theme in one they were not granted. That is the point of the model, not an edge case — the Environment is the isolation boundary, and it is authorized rather than merely structural.

Team roles

What you can do to the account: people, Environments, billing.
A Team always has at least one Owner. The last one cannot be demoted or removed, and cannot leave — promote somebody else first. Livry enforces this on both the demotion path and the departure path.
Billing is deliberately narrow. It exists so you can give your finance team an invoice without giving them your customers’ brands, which is why it carries no Environment grants — the role exists to withhold exactly that.

Environment roles

What you can do inside one Environment. Granted per Environment, per person. What Admin adds over Editor, in practice: changing a Theme’s integrations, its serving mode and signing keys, its allowlists, and the Environment’s own settings.
Creating an Environment grants you Admin on it. That is one of only four paths that write a grant — the others are accepting an invitation, an Admin editing a member, and signup (which creates no Environment, so writes no grant).

Worked combinations

That last row surprises people. It is correct.

Changing a role

A role change takes effect on the next request, not the next sign-in. There is no need to ask somebody to log out and back in. Team Admins and Owners manage this on the Team’s Members page.

Through the API

The Public API enforces exactly the same checks through exactly the same code — a Team Admin with no grant gets a 403 there too, and GET /environments lists only the Environments the caller was granted. Every Environment the API returns carries your role on it, so a client can tell whether a write will be refused before attempting it.
There is no role that is scoped to a single Theme or Variant. The finest scope Livry has is an Environment role, deliberately.If you want your own customers editing their own brand, build that against the API with your own authorization on top. Livry does not host a reseller-facing editor, and the access model has no scope that would make one safe.

Account-plane acts nobody can do through the API

Provisioning a Team, inviting or removing members, creating an Environment, and requesting deletion are portal-only. They write to the identity provider and the billing provider non-transactionally, and they send mail — a credential whose purpose is unattended automation should not be able to do any of it.