Business Accounts

Roles & Permissions

Every person on a business team has exactly one role: Admin, Writer, Reviewer, or Viewer. Each role has a distinct, fixed set of capabilities in the shared QR library.

The short version

  • Admin — can do everything, including billing, invitations and role changes. Also the only role that can delete someone else's work.
  • Writer — creates and edits codes, but cannot approve their own.
  • Reviewer — approves or rejects what Writers submit, but creates nothing.
  • Viewer — read-only, plus commenting and flagging.

The split that matters is between Writer and Reviewer: it exists so the person who makes a code isn't the person who signs it off. If you don't want that separation, give people Admin instead.

What each role can do

ActionAdminWriterReviewerViewer
View the shared library and comments
Create a new QR code (as a draft)
Edit a QR code's contentAnyOwn codes, at any status
Submit a draft for review✓ (own drafts)
Approve or reject a submission
Flag any code for review (a label only — see below)
Comment
Delete a QR codeAnyOwn drafts only
Invite/remove members, change roles

Note the deliberate asymmetry between the edit and delete rows. A Writer can edit anything they created no matter what state it's in, but can only delete their own work while it's still a draft. Editing is recoverable and leaves a reviewable trail; deleting an approved code that's already in print is not.

Editing an approved code

A Writer editing their own code doesn't need it to be a draft — they can change one that's already been approved and is in active use. That sounds alarming, so here's the rule that makes it safe:

Editing the content of an Approved code automatically resets it to Draft. It has to go back through review before it reads as Approved again.

So nobody can quietly alter something that already has sign-off and leave the "Approved" badge in place. The status label always means "the current content is what somebody actually reviewed" — never "this was approved at some point in the past." If you see Approved, that's the version that passed review.

Renaming a code counts as editing it, so a rename also sends it back to Draft. That's intentional — a name is often what a reviewer checked.

A note on "flag for review"

Any team member, including a Viewer, can flag any shared QR code for review — even one that's already Approved and in active use. This is deliberately just a status label: flagging a live code for review never disables it or changes what it does. It's a way to start a conversation ("this looks outdated, can someone check it?"), not a way to accidentally take something offline.

This is the one capability a Viewer has that changes anything at all, and it's specifically designed so it can't do damage. Someone who spots a poster pointing at a dead campaign page can raise it without needing a role that lets them break something.

Choosing roles for a real team

SituationSensible setup
Two or three people who all trust each otherEveryone Admin. The review workflow adds friction you don't need.
A marketing team with a manager who signs offManager Admin, everyone producing codes Writer.
Codes go to print and mistakes are expensiveWriters create, a separate person Reviewer, one Admin for membership.
Agency or client stakeholders who need visibilityViewer. They can see and comment without being able to change anything.

Frequently asked questions

Can one person hold more than one role?

Not directly — each person has exactly one role. In practice, Admin already covers everything Writer and Reviewer can do, so on a small team, making a second person Admin is the current way to give them full create-and-approve access. There's currently no way to combine, say, Writer and Reviewer without also granting Admin's billing and membership powers. This is a known gap we're tracking for a future update.

Can a Writer approve their own QR code?

No. A Writer can create a code and submit it for review, but only an Admin or a Reviewer can approve or reject it. That separation is the entire point of having the two roles. If you want one person to do both, make them an Admin — an Admin can approve their own submissions.

What happens if we only have one Admin and they leave?

You can't accidentally get into that state — removing the last Admin, or demoting them to another role, is refused with "A business must always have at least one admin." Promote someone else to Admin first, then remove or demote the original. The rule exists because Admin is the only role that can change roles, so a team with zero Admins would have no way to appoint one.

Does a Viewer seat still get their own personal QR codes?

Yes. Team roles only govern the shared library. Every member also has their own personal library and their own generator, entirely separate from the team's, and their role has no bearing on it. A Viewer on your team is still a full account holder in their own right.

Can a Reviewer fix a small mistake instead of rejecting it?

No — Reviewers cannot edit content, only approve or reject. Rejecting requires a comment explaining what needs to change, which goes back to whoever created it. If you want reviewers who can also correct things directly, make them Admins instead.