Skip to main content
Team & Access

Team roles and what each role can do

Every person on your StackJack team has a role, and the role decides which parts of the account they can manage. This page is the definitive capability matrix — use it whenever you're deciding what…

Written By Christopher Scaminaci

Last updated 6 days ago

Every person on your StackJack team has a role, and the role decides which parts of the account they can manage. This page is the definitive capability matrix — use it whenever you're deciding what role to give a teammate.

The four roles

The portal presents four customer-facing roles, although the primary owner and co-owners share the stored Owner role. The primary-owner designation identifies the one account anchor; it does not reduce a co-owner's day-to-day owner permissions.

RoleHow manyWhat it means
Primary OwnerExactly oneThe account's anchor: billing contact and identity-provider owner. Created with the account; changes only through an explicit ownership transfer.
Co-ownerAny numberFull account control, identical to the Primary Owner for day-to-day management — including billing and ownership changes.
AdministratorAny numberManages everything operational — connectors, subscriptions, AI-agent credentials, and the team — but cannot touch account billing, credits and the Anthropic BYOK key, ownership, region moves, or the organization data-deletion request. Their own AI-assistant tool set can still be restricted by an owner.
MemberAny numberNo management access. Members connect their AI assistants and use only the tools an admin has assigned to them.

Capability matrix

CapabilityPrimary Owner / Co-ownerAdministratorMember
Configure connectors (credentials, settings)✔✔✘
Manage connector subscriptions (upgrade, cancel)✔✔✘
Manage MCP clients and API keys✔✔✘
Manage the team (invite, approve, edit tools, suspend)✔✔✘
Buy credits and manage the Anthropic BYOK key (Automations → Credits)✔✘✘
Request permanent deletion of the organization's data (Team → Data & Privacy)✔✘✘
Create and edit custom tool roles, and assign them to members (Custom roles)✔✔✘
Configure Microsoft Entra directory sync (Directory sync)✔✔✘
Manage account billing✔✘✘
Grant/remove co-owners, change roles, transfer ownership✔✘✘
Start or cancel a self-service region migration✔✘✘
Connect an AI assistant and use assigned tools✔ (never member-restricted; a scoped credential still applies)✔ (assigned tools)✔ (assigned tools)

Three rules worth memorizing:

  • An owner is never restricted by their own member record. An owner's portal or browser sign-in resolves to every tool, and the Team page shows no Edit Tools button on an owner's row. A Client ID + Secret connection is a separate question: it serves exactly what that credential is scoped to on MCP Setup, even for an owner.
  • Tool restrictions do apply to Administrators, not only to Members. An owner scopes either one the same way. To narrow somebody who holds a custom tool role, change the role with Edit Roles — the tools button only adds extras on top of what their roles grant. An Administrator promoted from an unrestricted member keeps unrestricted tools until someone edits them.
  • Ownership, account billing, and region-migration initiation are owner-only. Administrators can manage individual connector subscriptions from Connectors, but cannot view the owner Billing details, change ownership, or start a region move.

Where roles appear in the portal

Team-role badges live on the Team page, under the Access & Team group in the left sidebar — its siblings there are Roles (custom tool roles) and Directory Sync:

  • Each member row shows a role badge — Owner, Administrator, or Member.
  • An "Understanding team roles" legend card on the same page summarizes what each role can do.

The Team page "Understanding team roles" legend card showing the Primary Owner / Co-owner / Administrator / Member descriptions
The Team page "Understanding team roles" legend card showing the Primary Owner / Co-owner / Administrator / Member descriptions

Roles vs. tool assignments

Roles and tool assignments are separate dials:

  • A role controls what someone can do in the portal (manage connectors, billing, the team).
  • A tool assignment controls what a Member's or Administrator's AI assistant can do through StackJack (which connector tools their agent may call). Owners cannot be tool-restricted through their member record.

For example, a Member with only HaloPSA read tools assigned can ask their AI assistant about Halo tickets but cannot see billing, change connectors, or call any other connector's tools. Changing a Member's tools is covered in Managing members.

A custom role is a third thing again, and the naming overlap is worth pinning down: it is a reusable bundle of tools you build once and reuse for as many people as you like — attached one at a time with Edit Roles on a member's Team row, a pending invitation, or an MCP endpoint — so you stop hand-picking a list per person. It grants no portal permissions at all. See Custom roles. If your organization runs Microsoft Entra, Directory sync can assign those custom roles from the Entra groups you already maintain, instead of assigning them here one person at a time.

Choosing the right role

  • Give Administrator to anyone who runs your MSP tooling day to day but shouldn't control payment or ownership.
  • Reserve Co-owner for people who genuinely need billing and ownership powers — it is full control, including the ability to remove other owners.
  • Keep everyone else a Member with a scoped tool assignment.

Next steps