ReferenceGaFor agencyFor operatorFor evaluator

Team roles and client handoff checklist

Assign the least access required and transfer every source, delivery, data and billing dependency deliberately.

Last updated 2026-08-28

What you'll achieve

  • Choose workspace and repository roles
  • Complete a client handoff
  • Preserve evidence before access changes

Role matrix

Role Intended use Key authority
Workspace owner Accountable customer or client owner Membership, billing authority and final workspace control
Workspace admin Trusted operational administrator Workspace and project administration without replacing the accountable owner
Workspace developer Delivery team member Build and project work within the workspace; no owner-only billing authority
Repository viewer Read-only source review View authorized repository activity
Repository developer Source contribution Pull, edit and propose source updates within policy
Repository deployer Release operator Start permitted delivery actions for allowed environments
Repository reviewer Approval responsibility Review protected changes without receiving owner authority
Repository admin Source-control administrator Repository policy and grants within the project
Collaboration viewer/reviewer/editor Time-limited file collaboration View, comment/review, or edit only the granted project document

Use separate client workspaces where clients must not see one another. Keep at least one client-controlled owner and avoid using a shared personal account.

Handoff checklist

Before the client accepts a handoff, record and verify: destination workspace and owner; repository authorization and final commit; source and evidence export; domains and DNS control; database bindings and independent live-data export; project assets; secret rotation responsibility; active releases; paid add-ons; invoice owner; monitoring contacts; and post-handoff support scope.

Acceptance changes project ownership and removes prior repository role grants so the destination can assign them again. It does not transfer a GitHub App installation, domain-registrar account, external database account, secret value, paid entitlement or separate supplier contract. Revoke or re-authorize each of those systems explicitly. The destination plan and limits apply after acceptance.

Authorized Enterprise administrators can request an integrity-checked source evidence export. The generated download expires after seven days. Export records required for a contract, dispute or audit before the applicable workspace retention expires.

Billing permissions

Workspace owners and admins can view and manage workspace billing. Developers do not have billing-management authority. BlinkHost does not currently provide a separate billing-viewer or account-manager role, so do not grant Admin merely to provide read-only invoice access. The workspace owner remains accountable for payment methods, plan changes, add-on purchases and cancellation.

Agency capability and evidence availability

The live Pricing comparison is authoritative for white-label delivery and portfolio observability. A plan is eligible only when the corresponding row says Included; repository ownership or an agency workspace does not unlock either capability. The add-on list now identifies every compatible public plan by name.

Source activity records cover the source-control action, actor and time. Authorized Enterprise administrators can request an integrity-checked source-evidence export; it is not included on a plan merely because a team can view recent activity in the dashboard. The generated evidence download expires after seven days. Agencies that require a particular export format, retention period or delivery time for a client dispute must contract for it and preserve their own accepted handoff record.

Help improve this page

Sign in to send page-specific feedback. For account-specific help, email support@blinkhost.me.

Team roles and client handoff checklist | BlinkHost