Buyer answers
Make access clear before client reporting spreads.
Agencies need clients, operators, strategists, and executives inside the same reporting motion without turning every user into an account administrator.
Buyer answerWhat roles does SIRJ support?
SIRJ uses owner, analyst, and viewer roles. Owners can manage the account, team, clients, integrations, billing, exports, and data administration. Analysts can inspect dashboards, ask source-backed questions, and export reports or data. Viewers can inspect dashboards and ask supported questions without administration privileges.
Agencies can involve operators, strategists, executives, and clients without giving every person the same ability to change sources, billing, exports, or data controls.
Follow the access pathBuyer answerCan a user be limited to one client workspace?
Yes. A membership can be scoped to all clients or to specific client ids. Client access checks require the membership account to match the client and the requested client to sit inside the user's allowed client list before permissions are evaluated.
A client viewer or analyst can be routed into one client workspace without exposing the agency portfolio or another client's reporting data.
Follow the access pathBuyer answerHow do invitations work?
Client invitations create pending, accepted, revoked, or expired access records. Invitations are limited to analyst or viewer roles, include a one-time token, and create a client-scoped membership when accepted before expiry.
The invite path lets an agency add clients or collaborators to a single workspace while preserving token handling, invite status, accepted user, expiry, and revocation evidence.
Follow the access pathBuyer answerWhich actions are restricted?
Billing, team management, client management, integration management, report export, data export, and data deletion require explicit permissions. The API runtime checks role and client scope before handling client, integration, billing, export, and compliance routes.
A polished report workflow does not require giving every user the ability to alter connections, run exports, delete data, or change billing.
Follow the access path