Released 2026-06-16. Team roles & access. Two new member roles, owner-delegated billing, read-only access for viewers, and per-resource (allowlist) access for developers and viewers.
New roles: Billing & Viewer
- Billing — manage the team's plan, payment methods, coupons, and invoices on the owner's behalf, without any access to resources or members. Invite someone from finance without handing over the workspace.
- Viewer — read-only across the team's workflows, forms, visualizers, playgrounds, streams, agents, and apps. Viewers can see and inspect but never create, edit, or run.
Owner, Admin, and Developer behave exactly as before. A billing member acts on the owner's subscription, so delegating billing never exposes the owner's personal payment surface beyond the team.
Scoped (allowlist) access
A developer or viewer can now be restricted to a hand-picked set of resources instead of everything their role allows. Open Manage access on a member, turn on Restrict to specific resources, then grant individual workflows, forms, visualizers, playgrounds, streams, agents, or apps at view or edit level. A restricted member sees only what they have been granted — an empty list means they see nothing. Grants are cleared automatically when a member is removed or leaves, so re-inviting them later never resurrects old access.
Notes
- Existing members are unaffected — scoping is off by default and every current role keeps its access.
- Your data export (My Account → Privacy Rights) now lists your scoped grants per team; account deletion purges them.