Skip to content
1 minute readSecurity

Workspace roles now limit what each person can do

In the dashboard, viewers and billing members can no longer create API keys, and only owners and admins can manage webhooks, store connections and workspace settings, while only owners, admins and billing members can move money.

Until now, belonging to a workspace was enough to do almost anything in it from the dashboard or the mobile app, whatever your role. Roles now decide:

  • API keys, agent keys and embed tokens: owners, admins and members can create and revoke them. Viewers and billing members cannot.
  • Webhooks, store connections and workspace settings: owners and admins. Listing webhooks also needs one, because the list shows signing secrets.
  • Money: balances, top-ups, refunds, credits, invoices and agent spending allowances need an owner, admin or billing member.

Anyone else gets a clear message saying which roles can do it. API keys and access tokens are unchanged: what they can reach is still set by their scopes. Keys created earlier by people whose role no longer allows it keep working until you revoke them, so review your keys if you have given viewers access.

For help, write to support@last-price.ai.