A person’s current role applies to their browser session, personal API keys and OAuth connections. API permissions cannot elevate a person beyond their role. Team API keys belong to the workspace and are managed by Admins; they do not depend on the creator remaining a member.
Database deletion in the browser asks an Admin to confirm their identity with a password or passkey. Other authorised operations execute directly; there is no approval-ticket workflow.
Team access
Invite people and choose Admin, Member or Viewer permissions.
Rootset serves one workspace per installation. Admins manage its people in Team Settings → Members. Invite a person by email and choose their role; SMTP delivers the invitation.
Was this page helpful?
