Seev PlusDocs
Docs
Settings

Team Access

Add teammates to an organization, choose a role, and grant only the permissions each person needs.

Team access lets several people work in one organization using their own Seev logins. The organization keeps its records when a member leaves, so removing someone costs you nothing but their access.

Choose a role

Every membership carries one of three built-in roles. They nest: an owner satisfies anything an admin can do, and an admin satisfies anything a member can do.

RoleSuited toAccess
OwnerThe business owner or primary account holderEvery permission in the organization.
AdminA trusted operations or finance leadEvery permission in the organization.
MemberEveryone elseOnly the permissions granted by an assigned custom role, plus the three permissions every member always holds.

Owner and admin both resolve to every permission, including moving money, revealing card details, managing API keys, and closing the organization. Admin is not a reduced form of owner. If you want a teammate to have less than total access, make them a member and give them a custom role.

Every active member, whatever their role, always holds dashboard.read, organization.read, and role.read. These cannot be taken away or stored on a custom role.

Grant only what someone needs

A custom role is a named set of permission keys. Assigning one makes the person a member and attaches the role, so their access is exactly the always-allowed three plus the keys on that role.

Permissions are grouped by the area they govern. Each is also classified by risk, so the ones that move money or expose secrets are marked as such where you assign them.

AreaPermission keys
Reportinganalytics.read
Organization profileorganization.update, organization.alerts.manage
Organization verificationorganization.verification.manage
Organization securityorganization.security.manage, organization.close
Team and rolesteam.read, team.manage, role.manage
Walletswallet.read, wallet.manage, wallet.deposit, wallet.withdraw, wallet.transfer
Bank transfersbank_transfer.read, bank_transfer.create
Cardscard.read, card.create, card.manage, card.fund, card.details.reveal
Yieldyield.read, yield.manage, yield.deposit, yield.withdraw
Customerscustomer.read, customer.manage
Invoicesinvoice.read, invoice.create, invoice.update, invoice.collect
Payment linkspayment_link.read, payment_link.create, payment_link.update, payment_link.publish
Stores and productsstore.read, store.manage, product.manage
Ordersorder.read, order.manage, order.pos.create
Developer accessdeveloper.read, developer.settings.manage, developer.keys.manage, developer.webhooks.manage
Payoutspayout_settings.read, payout_settings.manage

A few of these have consequences worth knowing before you grant them:

  • organization.security.manage allows setting and changing the organization's transaction PIN, which gates every sensitive money action.
  • card.details.reveal exposes full card numbers and CVVs. See Cards.
  • developer.keys.manage allows creating and rotating API keys, which act on the organization without any PIN prompt.
  • organization.close allows starting closure of the whole organization.

Add or update a teammate

  1. Confirm the correct organization in the sidebar selector.
  2. Open Settings, then Team.
  3. Add the teammate using their Seev identity or the invitation flow.
  4. Choose a built-in role, or make them a member and assign a custom role.
  5. Review the resulting access before confirming.

Role changes apply only to the selected organization. The same person can hold different roles in different organizations.

Managing team members needs team.manage, and creating or editing custom roles needs role.manage. Seeing the team at all needs team.read. If Team is missing from Settings, or the controls on it are unavailable, the account lacks the relevant key rather than having hit a bug.

An invitation sits as pending until the person accepts it, and can be revoked before then. A membership itself is either active or disabled; only an active membership grants any access at all, so a disabled member is denied even the permissions their role lists.

Understand what a blocked teammate is seeing

Permission failures in the dashboard show up in two different ways, and telling them apart saves a lot of guessing.

  • A missing sidebar item or hidden card. The navigation filters on the read permission for each area, so Balances needs wallet.read, Customers needs customer.read, Subaccounts and the Settings payouts card need payout_settings.read or payout_settings.manage, and the Developers group needs developer.read. A group with no visible items disappears entirely.
  • A refused request. An action the person can see but not perform is rejected by the server with an insufficient-permissions error.

Two sidebar items are hidden for reasons other than permissions: Cards appears only for organizations verified as a business, and Yield stays hidden until a yield account exists. See Cards and Yield.

When someone leaves

Remove their membership promptly. Their personal Seev login stays theirs; the organization keeps its stores, invoices, customers, balances, and reports.

Removing a membership does not rotate anything they knew. If they had the transaction PIN or an API key, change the PIN and rotate the key as well.

Credentials that are never shared

  • Login passwords
  • Transaction PINs
  • API secret keys
  • Webhook signing secrets
  • Full card details
  • Verification documents outside the upload flow

Giving someone their own membership and a custom role is always the right answer to "they need to do X". Sharing a credential is not.

Troubleshooting

Why can a member see a page but not act on it?

Their custom role grants the read key for that area without the corresponding manage, create, or update key.

Why does an admin still have access I meant to restrict?

Admin resolves to every permission. Restricting access means making the person a member with a custom role.

Why is a teammate denied everything despite having a role?

Check that their membership status is active. A disabled membership is refused regardless of role.

Can one person belong to several organizations?

Yes, with a different role in each. See Organizations.

On this page