Scott Holdings LLC
Design preview
GS
Organization Team Roles & permissions

Roles & permissions

What each role can do across the builder console. Truth lives in the effective-permissions view.

Permission matrix

Role changes happen on a member's detail page.

PermissionOwnerAdminDeveloperBillingViewer
Manage account settingsYesYes
Manage team membersYesYes
Create SaaS productsYesYesYes
Manage template packsYesYesYes
Deploy & provisionYesYesYes
Manage billingYesYesYes
Manage marketplace storeYesYes
Manage appliance packagesYesYes
Purchase marketplace productsYesYesYes
Install marketplace productsYesYesYes
View marketplace revenueYesYesYes
Source: vw_BuilderUserPermissions — never inferred from RoleCode.5 roles · 9 permissions
About this page

Maps builder-console permissions only. These roles authorize management of BuildWithHQ itself. Each provisioned SaaS has a separate tenant owner, user types, DataRoles, location scope, and record permissions inside its isolated core database.

Behind this page/team/roles · CanManageUsers

Retrieve

sp_Builder_ListRoles supplies the role set; vw_BuilderUserPermissions is the authoritative source of effective flags. Marketplace access is granular — CanManageMarketplaceStore, CanPurchaseMarketplace, CanInstallMarketplaceProducts, CanViewMarketplaceRevenue, CanManageMarketplacePayouts — enforced by fn_Marketplace_UserCan.

Save

Role changes are saved from the member detail page via sp_Builder_UpdateUserRole; this matrix itself is read-only.

Success

  • Builder permissions come from the effective builder-permissions view and are rechecked server-side.
  • BuilderUserId and tenant UserId are different identities.
  • Tenant DataRoles and DataRolesXref never grant builder-console access.
  • Owner overrides are explicit on each plane, never inferred across planes.

CLI handoff

Implement this scaffold from the structured contract, then remove hard-coded preview rows. The source of truth is CLI Handoff and admin-cli-manifest.json.

Page IDroles-permissions
Route/team/roles
AccessCanManageUsers
Statusjourney-aligned-scaffold

Server-inject identity and scope values; never trust browser-supplied account, app, tenant, user, entitlement, price, or permission identifiers. Preserve the loading, empty, forbidden, failed, retrying, and completed states shown by the preview.