Teams & roles.
Just the right reach.
Most identity platforms ship two roles and call it a day. Synq gives you the built-in Owner / Admin / Member trio plus custom roles you compose from a granular permission set — so the teammate who manages Discord credentials never accidentally edits your webhook secrets.
Start with three, customize when you need more
The defaults cover most teams. Add custom roles when you need to scope a specific teammate to a specific resource — for example, a developer-relations engineer who can manage webhooks and audit log but cannot rotate billing.
Owner
Full permissions across every resource. At least one Owner per Org. Owners can promote and demote other members.
Admin
Everything except billing management. Use Admin for teammates who run the platform day to day without owning the plan relationship.
Member
Read access to most resources; no write access by default. Pair Member with a custom role for the specific writes a teammate needs.
What you can grant
Every Synq surface has its own permission. Custom roles compose any subset — useful when you want to grant a teammate exactly one capability, not a blanket Admin role.
| Resource | What the permission grants |
|---|---|
| Profile | View / edit your own profile |
| Apps | View / edit OIDC clients under any Brand |
| Brands | View / edit branding, providers, scopes, emails |
| Members | View members, manage invitations and role bindings |
| Webhooks | View / edit webhook subscriptions and secrets |
| Token Gates | View / edit token-gate rules |
| Audit Log | Query the org audit log |
| API Keys | View / manage org and user API keys |
| Plan | View plan tier (Stripe billing portal stays user-bound) |
Email-only invites, role at acceptance
Send an invite by email. The invitee creates their Synq account (or signs into an existing one) and lands inside your Org with the role you picked. Invites expire if unaccepted; revoking one before it is accepted is a Dashboard click.
Read more
The three-tier model
Teams and roles live on the Org. See where that sits relative to Brands and Apps.
Brands
Brand-scoped configuration. Team members with Brand-edit rights can change theming and providers.
Apps
OIDC clients. Team members with App-edit rights can rotate secrets and update redirect URIs.
Common questions
Invite a teammate in under a minute.
Email address, role, send. Synq handles the rest — account creation if needed, Org membership, role binding, audit-log entry.
