> ## Documentation Index
> Fetch the complete documentation index at: https://docs.livry.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and Permissions in Livry

> Livry has two independent permission planes: a Team role for the account, and a per-Environment grant for the work. Neither implies the other.

Livry has **two independent planes**. Everybody holds exactly one Team role, and zero or more
Environment grants.

<Warning>
  **A Team role grants no access inside an Environment.**

  A Team Admin can create and delete Environments and still be unable to read a Theme in one they
  were not granted. That is the point of the model, not an edge case — the Environment is the
  isolation boundary, and it is authorized rather than merely structural.
</Warning>

## Team roles

What you can do to the **account**: people, Environments, billing.

| Role | Carries |
| - | - |
| **Member** | The default for a product user. Reaches Environments only through grants. No billing. |
| **Billing** | Billing information, and nothing else. **Holds no Environment grants at all.** |
| **Admin** | Member, plus creating and deleting Environments, and managing members. |
| **Owner** | Admin, plus initiating deletion of the Team. A Team may have several. |

<Note>
  **A Team always has at least one Owner.** The last one cannot be demoted or removed, and cannot
  leave — promote somebody else first. Livry enforces this on both the demotion path and the
  departure path.
</Note>

**Billing is deliberately narrow.** It exists so you can give your finance team an invoice without
giving them your customers' brands, which is why it carries no Environment grants — the role exists
to withhold exactly that.

## Environment roles

What you can do **inside** one Environment. Granted per Environment, per person.

| Role | Carries |
| - | - |
| **Viewer** | Read-only. The audience is auditors. |
| **Editor** | Edits Themes and Variants, edits tokens, publishes. No Environment administration. |
| **Admin** | Everything in the Environment **except deleting it** — that is an account-plane act. |

What Admin adds over Editor, in practice: changing a Theme's **integrations**, its serving mode and
signing keys, its allowlists, and the Environment's own settings.

<Note>
  Creating an Environment grants **you** Admin on it. That is one of only four paths that write a
  grant — the others are accepting an invitation, an Admin editing a member, and signup (which
  creates no Environment, so writes no grant).
</Note>

## Worked combinations

| Person | Team role | Grants | Result |
| - | - | - | - |
| Founder | Owner | Admin on all | Everything. |
| Frontend developer | Member | Editor on sandbox | Builds and publishes in sandbox; cannot see production at all. |
| Release engineer | Member | Editor on sandbox, Admin on production | Publishes anywhere; can rotate production signing keys. |
| Auditor | Member | Viewer on production | Reads production; changes nothing. |
| Finance | Billing | — | Invoices and plan. No themes. |
| New Team Admin | Admin | *(none)* | Can create Environments and manage people — and **cannot read a single Theme** until granted. |

That last row surprises people. It is correct.

## Changing a role

A role change takes effect **on the next request**, not the next sign-in. There is no need to ask
somebody to log out and back in.

Team Admins and Owners manage this on the Team's **Members** page.

## Through the API

The [Public API](/api/authentication) enforces exactly the same checks through exactly the same code
— a Team Admin with no grant gets a `403` there too, and `GET /environments` lists only the
Environments the caller was granted.

Every Environment the API returns carries your `role` on it, so a client can tell whether a write
will be refused before attempting it.

<Warning>
  **There is no role that is scoped to a single Theme or Variant.** The finest scope Livry has is an
  Environment role, deliberately.

  If you want your own customers editing their own brand, build that against the API with your own
  authorization on top. Livry does not host a reseller-facing editor, and the access model has no
  scope that would make one safe.
</Warning>

## Account-plane acts nobody can do through the API

Provisioning a Team, inviting or removing members, creating an Environment, and requesting deletion
are portal-only. They write to the identity provider and the billing provider non-transactionally,
and they send mail — a credential whose purpose is unattended automation should not be able to do any
of it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.