Team roles and client handoff checklist
Assign the least access required and transfer every source, delivery, data and billing dependency deliberately.
Last updated 2026-08-28
What you'll achieve
- Choose workspace and repository roles
- Complete a client handoff
- Preserve evidence before access changes
Role matrix
| Role | Intended use | Key authority |
|---|---|---|
| Workspace owner | Accountable customer or client owner | Membership, billing authority and final workspace control |
| Workspace admin | Trusted operational administrator | Workspace and project administration without replacing the accountable owner |
| Workspace developer | Delivery team member | Build and project work within the workspace; no owner-only billing authority |
| Repository viewer | Read-only source review | View authorized repository activity |
| Repository developer | Source contribution | Pull, edit and propose source updates within policy |
| Repository deployer | Release operator | Start permitted delivery actions for allowed environments |
| Repository reviewer | Approval responsibility | Review protected changes without receiving owner authority |
| Repository admin | Source-control administrator | Repository policy and grants within the project |
| Collaboration viewer/reviewer/editor | Time-limited file collaboration | View, comment/review, or edit only the granted project document |
Use separate client workspaces where clients must not see one another. Keep at least one client-controlled owner and avoid using a shared personal account.
Handoff checklist
Before the client accepts a handoff, record and verify: destination workspace and owner; repository authorization and final commit; source and evidence export; domains and DNS control; database bindings and independent live-data export; project assets; secret rotation responsibility; active releases; paid add-ons; invoice owner; monitoring contacts; and post-handoff support scope.
Acceptance changes project ownership and removes prior repository role grants so the destination can assign them again. It does not transfer a GitHub App installation, domain-registrar account, external database account, secret value, paid entitlement or separate supplier contract. Revoke or re-authorize each of those systems explicitly. The destination plan and limits apply after acceptance.
Authorized Enterprise administrators can request an integrity-checked source evidence export. The generated download expires after seven days. Export records required for a contract, dispute or audit before the applicable workspace retention expires.
Billing permissions
Workspace owners and admins can view and manage workspace billing. Developers do not have billing-management authority. BlinkHost does not currently provide a separate billing-viewer or account-manager role, so do not grant Admin merely to provide read-only invoice access. The workspace owner remains accountable for payment methods, plan changes, add-on purchases and cancellation.
Agency capability and evidence availability
The live Pricing comparison is authoritative for white-label delivery and portfolio observability. A plan is eligible only when the corresponding row says Included; repository ownership or an agency workspace does not unlock either capability. The add-on list now identifies every compatible public plan by name.
Source activity records cover the source-control action, actor and time. Authorized Enterprise administrators can request an integrity-checked source-evidence export; it is not included on a plan merely because a team can view recent activity in the dashboard. The generated evidence download expires after seven days. Agencies that require a particular export format, retention period or delivery time for a client dispute must contract for it and preserve their own accepted handoff record.
Help improve this page
Sign in to send page-specific feedback. For account-specific help, email support@blinkhost.me.