# Zulink

## Roles and permissions

> Category: Team and plans

---

## Pages


### Getting started

- [What is Zulink?](https://docs.zulink.co/getting-started/what-is-zulink)
- [Quickstart](https://docs.zulink.co/getting-started/quickstart)
- [Custom domains](https://docs.zulink.co/getting-started/custom-domains)

### Links

- [Creating links](https://docs.zulink.co/links/creating-links)
- [Targeting](https://docs.zulink.co/links/targeting)
- [A/B testing](https://docs.zulink.co/links/a-b-testing)
- [Link security](https://docs.zulink.co/links/link-security)
- [Social previews](https://docs.zulink.co/links/social-previews)

### Design and analytics

- [OpenGraph Designer](https://docs.zulink.co/design-and-analytics/opengraph-designer)
- [Analytics](https://docs.zulink.co/design-and-analytics/analytics)

### Team and plans

- [Members and invitations](https://docs.zulink.co/team-and-plans/members-and-invitations)
- [Roles and permissions](https://docs.zulink.co/team-and-plans/roles-and-permissions)

### AI agents

- [MCP Server](https://docs.zulink.co/ai-agents/mcp-server)

---

# Roles and permissions

Every member of a project holds a role, and a role is a list of permissions. Nothing in Zulink is decided by job title or seniority, only by that list.

Roles live under **Project settings → Roles**.

## The three system roles

| Role | What it can do |
| --- | --- |
| Owner | Everything, including billing and deleting the project |
| Administrator | Manages links, domains, designs, members, invitations, roles and API tokens; can see billing but not change it, and cannot delete the project |
| Member | Sees the project and its member list |

These three are protected: they cannot be renamed, edited or deleted, so the ground under your project never shifts. A new member starts as *Member* unless you pick something else.

## Custom roles

Sometimes the three defaults are too coarse. A marketing team may need to create links but must not touch domains; an agency should only read analytics. For cases like these, create your own role. It needs a name, an optional description explaining what it is for, and its permissions.

To make that quick, four templates are offered:

- **Read only** may see everything and change nothing.
- **Contributor** sees the project and its members, and may edit project details.
- **Manager** has the same permissions as the Administrator role.
- **Full access** has every permission there is.

Any template can be adjusted afterwards; the permission picker groups everything by area.

## The permissions

| Area | Permissions |
| --- | --- |
| Project | View, edit, delete |
| Members | View, invite, assign roles, remove |
| Invitations | View, create, revoke |
| Domains | View, add, remove |
| Links | View, create, edit, delete |
| OpenGraph designs | View, create, edit, delete |
| Analytics | View |
| API tokens | View, create, edit, delete |
| Roles | View, create, edit, delete |
| Billing | View, manage |

Permissions are cumulative and independent: granting *Create links* without *View analytics* is perfectly normal.

## How permissions take effect

Two things happen at once. The interface hides what you may not do, so a menu entry, a button or a whole page simply is not there rather than being shown greyed out. And every request is checked again on the server, where information you are not allowed to see is not sent to your browser in the first place.

The same applies to everything acting on your behalf: an [AI agent](https://docs.zulink.co/ai-agents/mcp-server) connected to your account, or a token used by a script, carries a role and can never exceed it.

## Changing and deleting roles

Editing a role takes effect immediately for everyone who holds it, including tokens and agent connections that were created earlier.

A role that still has members, open invitations or API tokens assigned cannot simply be deleted. Zulink tells you how many are affected and asks which role they should get instead, so nobody is left without one.

And the rule that overrides all of the above: **a project always keeps at least one owner.** The last one cannot be demoted or removed.
