# Grant per-app team access

Choose the affiliate role and permitted apps deliberately.

## What you need

Workspace-owner access and the teammate’s intended role/app scope. This feature governs affiliate workspace access.

## Steps

1. Open **Settings → Affiliate team** or **Affiliates → Team**.
2. Invite the teammate, choose their role and grant only the intended apps. The teammate accepts the invitation through its own account path.
3. Use viewer for read access, editor for permitted program/partner/referral/reward/integration work, and finance for authorized financial review/report/export operations.
4. Verify the teammate’s visible app scope and permitted actions. An editor does not automatically gain finance permissions.
5. Remove/revoke access when no longer needed and review active app grants after adding apps.

## Expected result

A teammate account bounded by its role and per-app grants; partner accounts remain limited to their own affiliate records.



## Troubleshooting

Check invitation expiry, account identity, granted app and action permission. Owner MCP and general workspace analytics credentials are a separate broad authority; do not share an owner key as a replacement for scoped team access.
