Permissions
Beyond the four roles, admins can fine-tune what each role — or group of members — may do, per feature.

- Roles matrix — for each role, toggle feature permissions (analytics activity, billing read, settings write, user management...). Reset restores the built-in defaults. Owner permissions can't be edited.
- Groups — create groups (e.g. "Platform team", "Auditors"), add members, and grant permissions to the group; members get the union of their role and group permissions.
A member's effective permissions are visible via My permissions. If someone can't see a page they expect (e.g. the Activity log needs the analytics:activity permission), check their role and groups here.