Metrickle

Team, roles and access

Last updated

A workspace holds your apps and the people who work on them. Each person has a role, which decides what they can see and change, and can be limited to some of the workspace's apps. You manage all of this on Team & workspace in the sidebar.

Roles

Every workspace has four built-in roles. They can't be changed.

RoleWhat they can do
OwnerEverything, including making other people owners.
AdminEverything except making owners. Owners and admins are the only roles that can change security settings.
MemberSees everything, works cases, triages feedback and files issues. Changes nothing else.
ViewerReads results only. No replays, screenshots, study participants' details, raw exports or the audit log.

Members and viewers can't see the audit log or Metrickle support sessions.

Custom roles

For anything in between, make your own role. For example, a researcher who can draft and launch surveys but not change app settings, or a client who can see results but not replays.

  1. On Team & workspace, go to Roles and choose New role.
  2. Enter a Name and, if you like, a Description.
  3. Under Permissions, tick a whole group, or open it to pick single permissions.
  4. Choose Create role.

You can only include permissions your own role has. A custom role can never make owners or change security settings: those stay with the built-in Owner and Admin roles. To delete a custom role, first give everyone who has it another role.

Invite people

  1. On Team & workspace, find Invite a teammate or client.
  2. Enter their Email and choose a Role. You can only hand out roles whose permissions you have yourself.
  3. Under App access, choose All apps, which includes apps added later, or Only some apps and pick them.
  4. Choose Create invitation.

The invite link is copied to your clipboard. Send it to your teammate yourself. Links stay valid for 7 days. Until they're accepted, invitations are listed under Pending invitations, where you can copy the link again or revoke it.

Limit someone to some apps

People only see the apps you choose, in the dashboard, the API and notifications. Other apps don't show up for them at all. This suits agencies sharing one workspace with several clients.

To change it, find the person under Members, choose their app access, and pick All apps or Only some apps. You can only share apps you can see yourself.

To change someone's role, use the role menu next to their name. To remove someone, use the remove button: they lose access to every app in the workspace, and so do their API tokens.

What only a person can do

Some permissions are never given to an API token or an AI assistant, whatever the token's role says. They're the promises and switches a person must make in the dashboard, including:

  • inviting people, changing roles and app access, and editing custom roles
  • choosing the plan and managing payment details
  • protecting a task, and dismissing a case
  • putting a survey live, and deleting feedback
  • changing app settings, rotating keys and hook URLs, deleting apps and erasing a visitor's data
  • setting up integrations, issue trackers and the warehouse export

A token acts as the person who made it and never has more access than they do. See API tokens.

Two-factor sign-in

Anyone can turn on two-factor sign-in for their own account:

  1. Open your name at the bottom of the sidebar, then Your settings.
  2. Under Two-factor sign-in, enter your password if asked and choose Turn on two-factor sign-in.
  3. Scan the QR code with an authenticator app, such as 1Password, Google Authenticator or Microsoft Authenticator, or type in the setup key.
  4. Enter the 6-digit code the app shows.
  5. Save your backup codes somewhere safe, such as a password manager, then choose I've saved my codes. If you lose your phone, sign in with a backup code instead. Each one works once.

Require it for everyone

Owners and admins can require two-factor sign-in for the whole workspace:

  1. Open Security in the sidebar.
  2. Under Sign-in rules, tick Require two-factor sign-in.
  3. Choose Save sign-in rules.

It applies straight away, including to people already signed in. Anyone who hasn't set it up is asked to before they can go on. Signing in through the workspace's single sign-on counts.

Sign-in rules can also sign people out after a set number of hours, and limit access to a list of IP addresses with Only allow these IP addresses. API tokens follow the IP list too. You can't save a rule that would lock yourself out.

Single sign-on (SSO)

Single sign-on lets people sign in with your identity provider, such as Okta, Microsoft Entra ID or Google Workspace. It's on the Pro, Agency and Enterprise plans.

  1. Open Security and, under Single sign-on, choose Add a connection.
  2. Choose OpenID Connect (OIDC) or SAML.
  3. Give your identity provider the values shown, then fill in what it gives you.
  4. Enter your Email domains and choose Add connection.
  5. Choose Verify domains, add the TXT records shown where you manage DNS, then choose Check DNS.

Nobody can sign in through the connection until its domains are verified. This proves the workspace owns the domains, so nobody else can sign people in from them.

Once a connection is verified, you can tick Require single sign-on under Sign-in rules. Owners can still sign in with their password and two-factor, so an outage at your identity provider can't lock everyone out. You can also choose the Role for people who join through single sign-on.

Directory sync (SCIM)

SCIM adds, updates and removes people automatically from your directory, such as Okta or Microsoft Entra ID. It's on the Enterprise plan.

  1. Open Security and find Directory sync (SCIM).
  2. Copy the SCIM base URL.
  3. Under Tokens, name a token and choose Make token. It's shown once. Paste both into your directory's SCIM settings.
  4. Map directory groups to roles, then choose Save group roles. Someone in several groups gets the role that can do the most.

Deactivating someone in your directory removes them from the workspace straight away. Owners are never changed or removed by the directory. Without a mapped group, a sync never changes a role someone set by hand. People are matched to existing accounts only when their email is on a verified domain.

Audit log

The audit log records who changed what in the workspace, who watched replays or exported data, and from where. Entries are never edited or deleted. Owners and admins can read it, and so can anyone whose custom role includes See and export the audit log.

  1. Open Audit log in the sidebar.
  2. Filter by Kind of entry: Team & roles, Security, Data reads or API changes. You can also filter by Person.
  3. To keep a copy, choose Export CSV or JSON Lines. Exports include every matching entry, up to 50,000.

More than one workspace

You can belong to several workspaces, each with its own apps, people, roles and plan. Switch between them with the workspace menu at the top of the sidebar. To make another, open that menu and choose New workspace.