Manage what each team member can access and do in Zenovay. Fine-tune permissions beyond basic roles.
Accessing Permission Settings
Navigate to Members
- Go to Settings → Team
- Click "Members" tab
- View all team members
Member List View
| Member | Role | Websites | Last Active | |
|---|---|---|---|---|
| John Smith | john@company.com | Admin | All | Today |
| Sarah Jones | sarah@company.com | Editor | 3 of 5 | Yesterday |
| Mike Wilson | mike@company.com | Viewer | 2 of 5 | 3 days ago |
Editing Member Permissions
Change Role
- Click member name
- Select "Edit Role"
- Choose new role
- Save changes
Permission Panel
┌─────────────────────────────────────────────────────┐
│ Sarah Jones - Permissions │
│ ─────────────────────────────────────────────────── │
│ │
│ Current Role: Editor │
│ │
│ Role: [Viewer ▼] [Editor ✓] [Admin] │
│ │
│ Website Access: │
│ ☑ marketing.company.com │
│ ☑ blog.company.com │
│ ☑ shop.company.com │
│ ☐ internal.company.com │
│ ☐ dev.company.com │
│ │
│ [Cancel] [Save Changes] │
└─────────────────────────────────────────────────────┘
Website-Level Permissions
Scale PlanRestricting Website Access
Limit members to specific websites:
- Edit member permissions
- Uncheck websites to hide
- Save changes
Access Modes
| Mode | Description |
|---|---|
| All websites | Access everything (default) |
| Selected websites | Only chosen sites visible |
| No websites | Account exists but no access |
Example Configuration
Marketing Team Member:
✓ marketing.company.com
✓ blog.company.com
✗ internal.company.com
✗ dev.company.com
Developer:
✗ marketing.company.com
✗ blog.company.com
✗ internal.company.com
✓ dev.company.com
Feature-Level Permissions
Enterprise PlanGranular Controls
Customize specific feature access:
| Feature | Options |
|---|---|
| Session Replay | View / Disabled |
| Heatmaps | View / Disabled |
| Revenue Data | View / Hidden |
| User Identification | View / Masked |
| Export | Enabled / Disabled |
Setting Feature Permissions
- Edit member
- Click "Advanced Permissions"
- Toggle features
- Save
Privacy-Focused Settings
Hide sensitive data:
- Mask PII: Hide personal information
- Hide Revenue: Remove revenue figures
- Disable Export: Prevent data downloads
Bulk Permission Management
Edit Multiple Members
Scale Plan- Select multiple members (checkboxes)
- Click "Bulk Edit"
- Choose action:
- Change role
- Update website access
- Remove all selected
Import/Export Permissions
Export current configuration:
- Go to Settings → Team
- Click "Export"
- Download CSV
Import updated configuration:
- Modify exported CSV
- Click "Import"
- Review changes
- Apply
Permission Groups
Enterprise PlanCreating Groups
Organize members into groups:
- Go to Settings → Team tab
- Click "Create Group"
- Name the group
- Set default permissions
- Add members
Example Groups
| Group | Role | Websites | Features |
|---|---|---|---|
| Marketing | Editor | Marketing sites | All |
| Sales | Viewer | All | No export |
| Development | Admin | Dev sites | All |
| Executives | Viewer | All | No replay |
Managing Groups
- Add/remove members
- Update group permissions
- Delete groups (members keep last permissions)
Temporary Access
Time-Limited Permissions
Enterprise PlanGrant temporary access:
- Edit member
- Enable "Temporary Access"
- Set expiration date
- Access auto-revokes
Use Cases
| Scenario | Duration |
|---|---|
| Contractor project | Project end date |
| Audit period | 30 days |
| Training | 1 week |
| Client review | 7 days |
Permission Inheritance
How Inheritance Works
Team Role (Base)
└── Website Access (Restricts)
└── Feature Permissions (Further restricts)
Example
Sarah Jones:
├── Role: Editor (can edit)
├── Websites: Marketing only
└── Features: No export
Result: Can edit marketing site but not export data
Viewing Effective Permissions
Permission Summary
See what a member can actually do:
- Click member name
- View "Effective Permissions"
Sarah Jones - Effective Permissions
Analytics:
✓ View dashboard
✓ View real-time
✓ View sessions
✓ View heatmaps
✗ Export data (disabled)
Configuration:
✓ Create goals
✓ Edit website settings
✗ Delete websites (role limit)
✗ Manage integrations (role limit)
Websites:
✓ marketing.company.com
✓ blog.company.com
✗ internal.company.com
✗ dev.company.com
Common Scenarios
External Consultant
Limited view access:
- Role: Viewer
- Websites: Relevant only
- Features: No export, masked PII
Department Manager
Department oversight:
- Role: Editor
- Websites: Department sites
- Features: All
Executive Dashboard
High-level only:
- Role: Viewer
- Websites: All
- Features: No session replay
Compliance Auditor
Temporary full access:
- Role: Viewer
- Websites: All
- Features: All (time-limited)
Troubleshooting
Permission Not Working
If settings don't apply:
- Have member log out/in
- Clear browser cache
- Check for conflicting rules
- Verify save completed
Can't Edit Certain Members
You can only edit members with:
- Lower role than yours
- Same or lower access level
Inherited vs Direct
If permission seems wrong:
- Check role permissions first
- Then website restrictions
- Then feature overrides
Audit Changes
View Permission History
See what changed:
- Go to Settings → Activity tab
- Filter by "Permission Changes"
- View timeline
Permission Change Log
| Date | User | Action | Target |
|---|---|---|---|
| Jan 15 | You | Changed role | Sarah → Editor |
| Jan 14 | Admin | Restricted sites | Mike |
| Jan 10 | You | Disabled export | Sarah |
Best Practices
Start Restrictive
Begin with minimal access:
- Assign Viewer role
- Grant specific website access
- Enable features as needed
Document Decisions
Keep record of:
- Why permissions granted
- Who approved
- Review date
Regular Reviews
Schedule permission audits:
- Monthly for large teams
- Quarterly for small teams
- After any security incident