Roles and Permissions
Principle of least privilege: give product/ops/dev/finance only what they need to avoid mistakes and risk.
Key Roles
- Account Holder: Sole owner; can sign agreements, manage tax/banking, add members.
- Admin: Almost everything except signing agreements.
- App Manager: Manage specific apps’ versions, IAP, TestFlight.
- Developer: Upload builds, manage TestFlight, view technical data.
- Marketing: Access App Analytics and Sales, cannot change versions.
- Finance: Access financial/payment reports.
- Access to Cloud Managed Distribution Certificates: For Xcode automatic signing.
Invite Members
- Go to Users and Access → “+”.
- Enter email, name, choose roles and app scope.
- Toggle finance, cloud signing, and key permissions as needed.
Best Practices
- Agreements/tax/banking only for Account Holder/Admin.
- Use dedicated machine/CI accounts for uploads to limit sensitive email exposure.
- Regularly revoke access for leavers and enforce 2FA.
