# Roles, permissions and organization API keys

- Date: 2026-10-03
- Categories: New, Security
- Tags: Account
- Author: The EvoHub team
- URL: https://changelog-dev.evohub.io/roles-permissions-and-organization-api-keys

> Every action in EvoHub now checks a permission. Build your own roles or start from ready-made ones, give keys to the organization rather than a person, and invite people with roles and teams in one step.

Who can do what in your organization is now decided by roles, and every screen and API call in EvoHub checks the permission it needs.

### Roles
- Admin, Member and Viewer are now roles like any other, listed on the new **Roles** page alongside the ones you create.
- Create your own roles with a permission picker, or start from ready-made roles for each product, such as On-Call Responder, Uptime Operator or Status Page Manager. Each one says in two sentences what it can and cannot do.
- Granting permission to change something also grants permission to see it, so a role can no longer edit what it cannot open.
- You can only hand out permissions you hold yourself.
- When your role changes, your session picks it up without signing out.
- Buttons and screens you do not have permission for are hidden or explain why, instead of failing when clicked.

### API keys
- **Organization keys** belong to the organization rather than a person. Each carries a role and can be limited to one team. Changing the role changes every key that uses it, and keys can be revoked at any time.
- Personal keys are created for an organization you choose, and can never do more than you can.

### Members and invitations
- Invite people with their roles and teams in one step.
- Removing a member also removes their roles, team memberships and API keys.
- An address can only have one pending invitation, and an invitation stops working if the person who sent it leaves the organization.
- Account settings are split into **My Profile** and **Organization**.

### Security
- Changing your password signs you out of every other session.
- After too many failed sign-in attempts, an account stays locked for 15 minutes, even if the correct password is entered.
- Email addresses typed with capital letters now sign in correctly.
