Team & roles
Team members & roles
Invite teammates, assign tenant-scoped roles, and protect owner invariants.
Related in the dashboard:
settings.team, invitations.show
QR Hero uses organisation-scoped roles so agencies can collaborate without sharing passwords.
Roles overview
| Role | Typical access |
|---|---|
| Owner | Full control, billing, plan changes, delete org |
| Admin | Manage codes, domains, team (except owner removal) |
| Superuser | Create/edit codes and analytics, limited billing |
| Basic | View and edit assigned codes only |
Permissions are granular — your plan may hide features like API tokens or virtual windows from Basic users.
Invite a teammate
- Open Settings → Team.
- Enter email and pick a role.
- QR Hero sends an invitation link valid for a limited time.
- Invitee accepts via email or registers a new account through the invitation URL.
Owner invariants
Every organisation must keep at least one Owner. The last owner cannot be demoted or removed until another owner is assigned.
Organisation switching
Users in multiple organisations switch context from the header dropdown. Roles are evaluated independently per org — being Owner in one client does not elevate you in another.
SSO and enterprise
Enterprise plans may enforce SSO via Settings → SSO, mapping identity provider groups to QR Hero roles. See admin documentation for SAML metadata exchange.
Remove access
Removing a member revokes dashboard and API tokens tied to that membership immediately. Audit logs record role changes for compliance reviews.