Help / Getting started / Team & roles
Team & roles
For admins · ~4 min read · Last reviewed 22 July 2026
Two tiers, zero mystery. Platform administration is one role; everything else is a functional role that shapes your view of the work — so the intern can annotate dashboards without being able to delete the agency.
The two tiers
admin — day-to-day administration is admin-only: inviting and managing users, client records, billing, access policies, and the compliance surfaces (privacy requests, audit log, security incidents). Admin is never handed out by a wizard — an existing admin has to grant it deliberately.
Functional roles — viewer, head-of-seo, tech-seo, analyst, content-strategist, link-pr, dev-lead, marketing-ops, and cmo. These do not unlock any admin screens. What they change: which quick links and widgets your Home screen leads with, and which quarterly scorecard chair you are accountable for (see OKRs & KPIs).
One deliberate exception sits between the tiers: alongside admins, head-of-seo and marketing-ops can edit a client’s data-source configuration — the Search Console property, analytics site id, and other source settings that feed the nightly ingestion — for clients they belong to.
viewer: for clients, executives, and anyone else who should see everything and change nothing.
Global vs per-client
Roles come in two scopes. Your global role lives on your account and is what gates administration (Settings → Users, Clients, Billing). Your per-client role is set on each client workspace you are assigned to. You can be head-of-seo on one client and viewer on another — useful when someone runs one account and merely audits a second.
Steps — inviting someone
- Go to Settings → Users (requires the admin role).
- Under Invite by email, enter their email, pick a role, and choose Send invite.
- Their account is created immediately and they receive an invitation email explaining how to sign in at seokestrel.com with that address (see Sign-up & sign-in).
- Assign them to client workspaces in Settings → Clients: pick the client, enter their email, choose a per-client role, and Assign.
Good to know
- Invitations can also happen during onboarding (step 4) — new teammates get the same invitation email. The wizard’s role menu is deliberately short and can never mint an admin.
- The email is a courtesy, not a gate: even if it never arrives, the invited person can simply sign in with that address.
- Role changes and client assignments are recorded in the audit log — admins can see who promoted whom, and when, forever.
FAQ
- What role should my client get?
- viewer, almost always — the read-only seat for clients and executives: dashboards and reports, nothing to break.
- Who can connect Google Search Console?
- Any signed-in user can connect their own Google account under Settings → Integrations — the grant belongs to whoever gives it. Pointing a client at a property (its data-source settings) takes admin, head-of-seo, or marketing-ops.
- Can someone be in two clients with different roles?
- Yes — roles are assigned per client. Platform admin is separate and rarer.