# Permissions

Roles control what team members can see and change. Manage them from **Team Settings** > **Roles**.

## Access levels

A permission can include one or more access levels:

- **Read**: View the feature and its data.
- **Write**: Create or update items.
- **Delete**: Remove items.

These levels are independent. For example, someone can be allowed to view a project without being
allowed to change or delete it.

## Permission areas

The role editor shows the complete, current list of permission areas. Broadly, they cover:

- **Team management**: Users, roles, API keys, billing, and security logs.
- **Data setup**: Projects, sources, ingest keys, and servers.
- **Data and monitoring**: Records, views, facets, drains, metrics, monitors, and alerts.
- **Product features**: Pages, custom domains, Chat, and secrets.

Member roles always retain read access to projects so that project navigation works.

## Create or update a role

1. Open **Team Settings** and select **Roles**.
2. Create a role or open any existing role except **Owner**.
3. Select the access levels the role needs.
4. Save the role.

Use **Quick fill** to start with **Common** or **Full access**, then adjust the selection before
saving. **Clear** removes optional access while retaining the project read access required for team
members.

## Missing access

Tailglow keeps product sections visible even when your role cannot open their data. Selecting a
restricted section shows which permission is missing. Ask a team administrator to grant it.
Actions you cannot perform are hidden or disabled.

## API keys

API keys use the same permission areas but are not human roles. They do not require project read
access, and **Clear** removes all of their permissions. Give each key only the access its integration
needs. See [API Keys](/guides/api-keys) for setup and security guidance.
