Who can do what
Owners, admins and members — what each can reach, how invitations work, and why the last owner can't leave.
Three roles, and the difference between them is really one question: how much damage can this person do on a bad night. Your team is free on every plan, so the answer should never be "we only gave them access because it was cheaper".
The three roles
- Owner — full access, including billing. Owners can change the plan, the payment method and the people.
- Admin — manages the venue. Everything operational: bookings, menu, link hub, settings, events, and inviting staff. No billing.
- Member — runs service. Sees the book and works the floor; settings are read-only.
Most restaurants want one or two owners and everyone else an admin or member. The useful line is billing: an admin can run your restaurant and cannot change what you pay.
Members are read-only on the surfaces that shape your shopfront. The menu editor and the link hub both say so — "Owners and admins can edit" — so a member can look up a dish or check a link during service without any chance of publishing a half-finished card to your QR codes.
Inviting someone
Type their email address, pick a role beside it, and send.
The invitation is emailed as a link that lasts seven days, and it appears in Pending invitations with its expiry until it's accepted — where you can cancel it if you sent it to the wrong address.
Who you can invite depends on who you are: admins can invite admins and members; only owners can invite other owners. An admin cannot promote anyone past themselves, which is the property that makes handing out the admin role safe.
The role list is shown with its description at the point of choice rather than in a separate legend, so nobody has to remember what "admin" means while typing an email address.
Changing a role later
Roles are changed in place on the member's row — no re-invitation, and the change takes effect immediately.
One change is refused, and the message says exactly why:
You can't change the last owner's role — assign another owner first.
The same guard covers leaving and being removed: "You're the only owner — invite another owner first", and "This is the last owner — assign another owner first."
An account with no owner has nobody who can pay the bill, restore access, or add the next person — it is not a locked door, it is a building with no doors. So the system refuses the step that would create one, in all three directions, rather than warning you and letting it happen.
If you're leaving the business, the order is: invite your successor as an owner, wait for them to accept, then leave. Doing it in the other order is the one thing this surface won't let you do.
What a team costs
Nothing. Team members are free on every plan, and there is no per-person charge and no cap on how many people you invite.
This is worth stating plainly because the word seat appears on your invoice and means something else there. A seat on your bill is a location, not a person — three venues is three seats, whether five people or fifty can log in. Adding a colleague never changes what you pay. See Adding a second location.
When someone can't get in
A person who is not on the team for a venue doesn't get "access denied" — they get a page that doesn't exist.
That is deliberate. A 403 confirms the venue is there and that you're not welcome; a 404 says nothing at all. Since the admin address contains your venue's handle, an error that distinguished "no such venue" from "not your venue" would let anyone check which venues are on the platform by typing addresses.
So if a colleague reports that a link is broken, check the team list first. A missing invitation and a wrong URL look identical from their side, by design.
Good hygiene
- Remove people when they leave. An old member is a live login to tonight's book.
- Keep two owners. One owner is one lost phone away from a bad week.
- Prefer member for seasonal staff. They can run service without reaching settings.
- Watch the pending list. An invitation that's been sitting unaccepted for six days is about to expire, and expiry is silent.