Team Access
Add teammates to an organization, choose a role, and grant only the permissions each person needs.
Team access lets several people work in one organization using their own Seev logins. The organization keeps its records when a member leaves, so removing someone costs you nothing but their access.
Choose a role
Every membership carries one of three built-in roles. They nest: an owner satisfies anything an admin can do, and an admin satisfies anything a member can do.
| Role | Suited to | Access |
|---|---|---|
| Owner | The business owner or primary account holder | Every permission in the organization. |
| Admin | A trusted operations or finance lead | Every permission in the organization. |
| Member | Everyone else | Only the permissions granted by an assigned custom role, plus the three permissions every member always holds. |
Owner and admin both resolve to every permission, including moving money, revealing card details, managing API keys, and closing the organization. Admin is not a reduced form of owner. If you want a teammate to have less than total access, make them a member and give them a custom role.
Every active member, whatever their role, always holds dashboard.read, organization.read, and role.read. These cannot be taken away or stored on a custom role.
Grant only what someone needs
A custom role is a named set of permission keys. Assigning one makes the person a member and attaches the role, so their access is exactly the always-allowed three plus the keys on that role.
Permissions are grouped by the area they govern. Each is also classified by risk, so the ones that move money or expose secrets are marked as such where you assign them.
| Area | Permission keys |
|---|---|
| Reporting | analytics.read |
| Organization profile | organization.update, organization.alerts.manage |
| Organization verification | organization.verification.manage |
| Organization security | organization.security.manage, organization.close |
| Team and roles | team.read, team.manage, role.manage |
| Wallets | wallet.read, wallet.manage, wallet.deposit, wallet.withdraw, wallet.transfer |
| Bank transfers | bank_transfer.read, bank_transfer.create |
| Cards | card.read, card.create, card.manage, card.fund, card.details.reveal |
| Yield | yield.read, yield.manage, yield.deposit, yield.withdraw |
| Customers | customer.read, customer.manage |
| Invoices | invoice.read, invoice.create, invoice.update, invoice.collect |
| Payment links | payment_link.read, payment_link.create, payment_link.update, payment_link.publish |
| Stores and products | store.read, store.manage, product.manage |
| Orders | order.read, order.manage, order.pos.create |
| Developer access | developer.read, developer.settings.manage, developer.keys.manage, developer.webhooks.manage |
| Payouts | payout_settings.read, payout_settings.manage |
A few of these have consequences worth knowing before you grant them:
organization.security.manageallows setting and changing the organization's transaction PIN, which gates every sensitive money action.card.details.revealexposes full card numbers and CVVs. See Cards.developer.keys.manageallows creating and rotating API keys, which act on the organization without any PIN prompt.organization.closeallows starting closure of the whole organization.
Add or update a teammate
- Confirm the correct organization in the sidebar selector.
- Open Settings, then Team.
- Add the teammate using their Seev identity or the invitation flow.
- Choose a built-in role, or make them a member and assign a custom role.
- Review the resulting access before confirming.
Role changes apply only to the selected organization. The same person can hold different roles in different organizations.
Managing team members needs team.manage, and creating or editing custom roles needs role.manage. Seeing the team at all needs team.read. If Team is missing from Settings, or the controls on it are unavailable, the account lacks the relevant key rather than having hit a bug.
An invitation sits as pending until the person accepts it, and can be revoked before then. A membership itself is either active or disabled; only an active membership grants any access at all, so a disabled member is denied even the permissions their role lists.
Understand what a blocked teammate is seeing
Permission failures in the dashboard show up in two different ways, and telling them apart saves a lot of guessing.
- A missing sidebar item or hidden card. The navigation filters on the read permission for each area, so Balances needs
wallet.read, Customers needscustomer.read, Subaccounts and the Settings payouts card needpayout_settings.readorpayout_settings.manage, and the Developers group needsdeveloper.read. A group with no visible items disappears entirely. - A refused request. An action the person can see but not perform is rejected by the server with an insufficient-permissions error.
Two sidebar items are hidden for reasons other than permissions: Cards appears only for organizations verified as a business, and Yield stays hidden until a yield account exists. See Cards and Yield.
When someone leaves
Remove their membership promptly. Their personal Seev login stays theirs; the organization keeps its stores, invoices, customers, balances, and reports.
Removing a membership does not rotate anything they knew. If they had the transaction PIN or an API key, change the PIN and rotate the key as well.
Credentials that are never shared
- Login passwords
- Transaction PINs
- API secret keys
- Webhook signing secrets
- Full card details
- Verification documents outside the upload flow
Giving someone their own membership and a custom role is always the right answer to "they need to do X". Sharing a credential is not.
Troubleshooting
Why can a member see a page but not act on it?
Their custom role grants the read key for that area without the corresponding manage, create, or update key.
Why does an admin still have access I meant to restrict?
Admin resolves to every permission. Restricting access means making the person a member with a custom role.
Why is a teammate denied everything despite having a role?
Check that their membership status is active. A disabled membership is refused regardless of role.
Can one person belong to several organizations?
Yes, with a different role in each. See Organizations.