Grant per-app team access
Choose the affiliate role and permitted apps deliberately.
On this page
What you need
Workspace-owner access and the teammate’s intended role/app scope. This feature governs affiliate workspace access.
Steps
- Open Settings → Affiliate team or Affiliates → Team.
- Invite the teammate, choose their role and grant only the intended apps. The teammate accepts the invitation through its own account path.
- Use viewer for read access, editor for permitted program/partner/referral/reward/integration work, and finance for authorized financial review/report/export operations.
- Verify the teammate’s visible app scope and permitted actions. An editor does not automatically gain finance permissions.
- Remove/revoke access when no longer needed and review active app grants after adding apps.
Expected result
A teammate account bounded by its role and per-app grants; partner accounts remain limited to their own affiliate records.
Troubleshooting
Check invitation expiry, account identity, granted app and action permission. Owner MCP and general workspace analytics credentials are a separate broad authority; do not share an owner key as a replacement for scoped team access.