Seats, roles, and who can spend
The house owns the work and the wallet — not the person who made it. Four roles, one of which can spend real money and one of which cannot spend anything.
The house owns everything. Every image, every collection, every model you bought, every token and every API key belongs to the organisation, not to the person who made it. Take someone off the team and the work stays, with their name still on it.
That is the single most important thing to know about seats, because it is what makes the rest safe.
The four roles
| Role | May develop (spend tokens) | May spend money | May manage seats |
|---|---|---|---|
owner | yes | yes | everyone, including admins |
admin | yes | no | members and viewers only |
member | yes | no | no |
viewer | no | no | no |
Real money is owner-only. Starting or changing a subscription, buying a
top-up pack, buying anything in Explore, turning on auto top-up — one seat, on
purpose. A leaked session belonging to an admin cannot reach the card.
A viewer cannot develop at all. They can see the house's work and cannot
spend a token of it. That is the seat for a client, a buyer, or anyone who needs
to look without a bill attached.
Offering a seat
An owner or an admin can offer a seat. Only an owner can offer an
owner's seat.
The offer lapses after 48 hours and sits visibly in the register until it is taken, so the same seat does not get offered twice by two people who each thought nobody had.
Changing and emptying a seat
- Leaving is always yours. You can remove your own seat without asking.
- You cannot change your own role. Ask an owner.
- An
adminmay re-seat or remove amemberor aviewer, and may not touch anotheradminor the owner. - An
ownermay do any of it.
Emptying a seat takes nothing away from the house. Everything that person developed stays, attributed to them.
Handing the house over
owner is reachable one way only: the transfer, which is owner-only and demotes
the outgoing owner in the same movement. A house never has two owners and never
has none.
Your own powers change everywhere at once when this happens — the money lines in billing, the buy buttons in Explore — so the studio reloads around you.
A revoked seat, and the five minutes
Authority is re-read from the register on every write and every spend, so a removed seat stops being able to develop or spend immediately.
Read access can lag by up to five minutes, because the session is cached for that long. If you have just removed someone in a hurry, that is the window: they cannot do anything, and they may still see a page for a few minutes.
One level, deliberately
An organisation is the brand. There are no sub-organisations, no teams inside a house and no nesting. If you run two brands, run two houses.
Related
Invitations and invitation codes
FLAM is invite-only. Two doors — an invitation sent to your address, or a shareable code you paste at the door. Both end at the same gate, and neither bypasses it.
API keys, and letting an agent into the house
A key belongs to the house, not to a seat, so removing a person cannot orphan a running integration. Two roles, neither of which reaches money, and revocation that takes effect on the next request.