Choose the narrowest useful role
Billing and role assignment belong to an Owner and nobody else. An Admin issues seat invitations and signs off on operational approvals without touching billing. Anyone who needs to build audits, launch crawls, and act on findings should hold Member. A Viewer reads finished evidence and alters nothing. Seats are consumed by open invitations as well as active people, so withdraw any invitation that will not be accepted.
Protect authentication and tokens
Use the password reset route when access is lost. Integration tokens are stored for the connected workspace, while API tokens are displayed only at creation and retained as one-way digests. Never place an API token in a URL.
Review access after team changes
Remove stale invitations, reduce roles when responsibilities change, disconnect unused customer integrations, and rotate exposed API credentials. Confirm ownership before the only owner leaves a workspace.