Skip to content
Start In Cloud

Roles and Permissions

Access control over your analytics data should live on your infrastructure — not in a third-party identity cloud you don’t control. HitKeep’s role-based access control (RBAC) is enforced entirely on your instance, with granular roles at both the instance level and per site.

Instance roles apply across the entire HitKeep installation.

RolePermissions
ownerFull access — users, all sites, system settings
adminCan view all sites; cannot modify system settings
userAccess only to explicitly assigned sites

Change a user’s instance role (admin only) via:

Deleting a user is blocked if that user is the last owner of any team. Transfer team ownership first, then retry the instance-level delete. This prevents orphaned teams that no one can manage anymore.

HitKeep administration users page with instance roles and security actions
Administration → Users gives instance owners the global view for roles, account state, and emergency security actions such as disabling MFA.

Site roles are scoped per user, per site. A user can be a viewer on one site and an owner on another.

RoleWhat they can do
ownerFull site access — data, goals, funnels, team, retention settings
adminManage data, goals, funnels, and team members
editorCreate and edit goals and funnels
viewerRead-only access to dashboard and analytics

An invitation email is sent to the address. The user accepts via a link — no admin approval flow required on your end.

For CI pipelines, integrations, or automated dashboards, use API Clients instead of sharing user credentials. API client tokens are bearer tokens that can be revoked individually without affecting any other user or session.

HitKeep Cloud adds managed user provisioning with tenant-aware isolation and a hosted login flow, while keeping your analytics portable. Start with HitKeep Cloud →