Ability Reference
The complete list of permissions you can grant through roles or groups in Subscriby, entity by entity.
This page is the reference you'll keep open while setting up roles and groups. It lists every permission Subscriby exposes, what it governs, and a plain-English description of what a teammate holding it can do.
How permissions are structured
Every permission has two parts, joined with a colon:
{entity}:{action}- Entity — the thing the permission acts on (e.g.
project,project-access-code). - Action — what you can do with it (e.g.
view,create,delete).
There are 12 entities, each with 5 actions, for 60 permissions in total; the team-member entity spells its five actions differently (invite, remove and update-role rather than create, update and delete). Every count on this page is written from the permission catalogue on each build.
The five actions
| Code | Meaning |
|---|---|
view-any | See the list of all items in this entity (e.g. see every subscription, every plan). |
view | Open a specific item to inspect its details. |
create | Add a new item. |
update | Edit an existing item. |
delete | Remove an item permanently. |
view-any is listing access; view is detail access. In most cases you'll
want a role to have both — but splitting them lets you grant "can see this
specific thing in reports" without granting "can browse all of them".
Permissions by entity
Project (project)
Controls the project itself — the top-level container for a membership.
| Permission | What it lets the member do |
|---|---|
project:view-any | See the list of projects they have any access to. |
project:view | Open and inspect a project's settings and dashboard. |
project:create | Create new projects under your account. |
project:update | Edit a project's name, description, banner, handle, legal URLs, and other settings. |
project:delete | Permanently delete a project and all of its data. |
Project payment method (project-payment-method)
Controls which payment providers (Stripe, PayPal, Razorpay, etc.) are enabled on a project.
| Permission | What it lets the member do |
|---|---|
project-payment-method:view-any | See which payment methods are set up on the project. |
project-payment-method:view | Open a payment method's configuration. |
project-payment-method:create | Add a new payment provider to the project. |
project-payment-method:update | Edit an existing payment method's API keys or settings. |
project-payment-method:delete | Remove a payment provider from the project. |
Project resource (project-resource)
Controls the places linked to a project — the channels, groups, servers and manual perks a subscriber actually gets access to.
| Permission | What it lets the member do |
|---|---|
project-resource:view-any | See all linked resources. |
project-resource:view | Open a specific resource and see its members / status. |
project-resource:create | Link a new place or manual perk to the project. |
project-resource:update | Edit an existing resource's link or settings. |
project-resource:delete | Unlink a resource from the project. |
Project access code (project-access-code)
Controls promotional / free-access codes that members redeem to get discounted or free subscriptions.
| Permission | What it lets the member do |
|---|---|
project-access-code:view-any | See all access codes and their usage. |
project-access-code:view | Open a code and see redemption history. |
project-access-code:create | Generate new codes (single-use or batch). |
project-access-code:update | Edit an existing code's terms (expiry, plan, etc.). |
project-access-code:delete | Revoke a code. |
Project coupon (project-coupon)
Controls discount codes — one code that any number of subscribers can redeem for a percentage or fixed amount off. Requires the Coupons addon or the Growth plan.
Distinct from access codes: an access code is one string for one person and grants access outright, while a coupon is one string for many people and reduces what they pay.
| Permission | What it lets the member do |
|---|---|
project-coupon:view-any | See all discount codes, their limits, and how many times each was redeemed. |
project-coupon:view | Open a code and see its terms and redemption history. |
project-coupon:create | Create a new discount code. |
project-coupon:update | Edit a code's discount, limits, dates, or turn it on and off. |
project-coupon:delete | Delete a code. Refused while a checkout using it is still in progress. |
Project subscription (project-subscription)
Controls existing subscriptions that members have taken out — the purchases side.
| Permission | What it lets the member do |
|---|---|
project-subscription:view-any | See the list of active, trialling, expired, and one-time subscriptions. |
project-subscription:view | Open a specific subscription to see its payment history and status. |
project-subscription:create | Manually add a subscription for a member (bypass signup flow). |
project-subscription:update | Edit a subscription (e.g. override renewal date, change plan). |
project-subscription:delete | Cancel / remove a subscription. |
Project subscription plan (project-subscription-plan)
Controls the plans you offer — "$9.99/month Premium", "$99 one-time Lifetime", and so on.
| Permission | What it lets the member do |
|---|---|
project-subscription-plan:view-any | See the list of plans. |
project-subscription-plan:view | Open a plan to inspect pricing, trial, features, and billing cycle. |
project-subscription-plan:create | Create new plans. |
project-subscription-plan:update | Edit existing plans (price, trial, availability). |
project-subscription-plan:delete | Delete a plan (won't be offered to new subscribers). |
Project user (project-user)
Controls the members of a project — the end subscribers. Grants access to the member list, search, exports, and manual account actions.
| Permission | What it lets the member do |
|---|---|
project-user:view-any | See the list of all subscribers / members on the project. |
project-user:view | Open a specific member's profile, subscription history, and metadata. |
project-user:create | Manually add a subscriber (no payment required). |
project-user:update | Edit a subscriber's email, metadata, or magic-link status. |
project-user:delete | Remove a subscriber from the project. |
Project connector (project-connector)
Controls the Connectors a project runs — the platforms it gates access on, messages through and takes payments from. The directory itself (which connectors exist, what each can do, the form that connects one) is the same for every creator and only asks for the list permission; a project's installations, with their state and health, are what the Connectors tab shows. Connecting an installation (typing the credential) stays a dashboard act; the three write permissions cover everything around it.
| Permission | What it lets the member do |
|---|---|
project-connector:view-any | Browse the Connectors Marketplace and list a project's installations with their health. |
project-connector:view | Read one installation of a project by connector. |
project-connector:create | Install a connector on a project (a pending installation the creator then connects). |
project-connector:update | Verify an installation and change its declared settings. |
project-connector:delete | Disconnect an installation; the credentials are wiped and the row stays. |
Project recovery (project-recovery)
Controls the Disaster Recovery ledger — the incidents the health probes opened, the recoveries run, the quota and the readiness checklist — and the controls around it: the per-project failover settings, the standbys, the undo and the reminders. The ledger belongs to the account holder, so a teammate with the read permissions reads the owner's recovery, not their own; the write permissions let a token reach the write endpoints, but the actions behind them still refuse anyone but the project owner, exactly as the dashboard does.
| Permission | What it lets the member do |
|---|---|
project-recovery:view-any | List the incidents, the recoveries with their undo state, the allowances and readiness. |
project-recovery:view | Open one incident or recovery and read its re-admission roll call. |
project-recovery:create | Swap a resource onto its standby, and ask the creator to pick a standby or a replacement. |
project-recovery:update | Change failover settings and the standby mirror, remind members, undo a recovery, send the handover mail. |
project-recovery:delete | Remove a standby or the standby installation, and withdraw an open request. |
Support conversation (support-conversation)
Controls the member support inbox — the threads that open when a subscriber messages your bot with something it does not recognise.
| Permission | What it lets the member do |
|---|---|
support-conversation:view-any | See the inbox: every open, assigned and resolved thread on the project. |
support-conversation:view | Open a thread and read its messages. |
support-conversation:create | Start a thread with a subscriber rather than waiting for them to write in. |
support-conversation:update | Reply, add a private note, assign the thread, resolve it, or reopen it. |
support-conversation:delete | Delete a thread and its messages permanently. |
Team member (team-member)
The one entity whose five actions are not plain CRUD — membership is invited and removed rather than created and deleted, and changing someone's role is its own action.
| Permission | What it lets the member do |
|---|---|
team-member:view-any | See everyone on the team and the role each of them holds. |
team-member:view | Open a single member and inspect their role and group memberships. |
team-member:invite | Send an invitation to join the team. |
team-member:remove | Remove someone from the team. |
team-member:update-role | Change which role someone holds. |
Suggested role templates
You don't have to use these — but they're a solid starting point.
Community Manager
Handles day-to-day member interactions. No billing or plan changes.
project:view-any,project:viewproject-resource:view-any,project-resource:viewproject-subscription:view-any,project-subscription:viewproject-user:view-any,project-user:view,project-user:updateproject-access-code:view-any,project-access-code:view
Billing Admin
Handles plans and payment methods. No member data access.
project:view-any,project:viewproject-payment-method:*(all five actions)project-subscription-plan:*(all five actions)project-subscription:view-any,project-subscription:view
Read-only Auditor
External accountant or consultant — sees everything, changes nothing.
- Every
*:view-anyand*:viewpermission. - None of
create,update,delete.
Full Admin
Trusted deputy who does everything you do.
- All 60 permissions.
- Use sparingly — prefer narrower roles where possible.
Related
- Roles — apply these permissions as named, reusable bundles.
- Groups — layer extra permissions onto specific members.
- Invite members — pick the starting role when adding someone to the team.
How is this guide?
Groups
Define ad-hoc permission collections, attach specific members to them, and layer extra access on top of roles.
Disaster Recovery Program
What happens when a platform bans or restricts the account you sign in with, the bot that serves a project or a place your plans grant — how Subscriby detects it, how you recover in minutes with every paying member re-admitted automatically, and the fair-use rules that keep the program honest.