Team Roles and Permissions
URLcut.ai has three team roles: read, write and admin. They form a ladder, so each role grants everything the role below it grants, plus its own additions. This page lists every action each role allows.
What each role can do
| Action | Read | Write | Admin |
|---|---|---|---|
| View analytics for links and campaigns | |||
| Share a client report | — | ||
| Create a link | — | ||
| Edit a link | — | ||
| Deactivate a link (stop it without releasing the short code) | — | ||
| Create and manage campaigns | — | ||
| Delete a link permanently | — | — | |
| Invite, remove and re-role teammates | — | — | |
| Rename or delete a client, brand or campaign | — | — |
An unknown role grants nothing. Access is default-deny: a permission is allowed only when the role explicitly carries it.
Why deleting a link is admin-only
Deactivating a link and deleting a link are different actions in URLcut.ai, and only one of them is reversible.
Deactivating a link stops it and keeps the short code reserved. The link stops resolving, its click history stays, and nobody else can claim the short code. Anyone with the write role can do this, so a campaign executive who spots a link pointing at the wrong page can stop it immediately without waiting for an admin.
Deleting a link is permanent and releases the short code back into the pool. The record is removed with no history and no undo, and the short code becomes available for anyone to claim. If that code is printed on a QR code, sitting in a scheduled email, or live in an ad, whoever claims it next inherits that traffic. That is why the write role gets deactivate and the admin role gets delete.
Where a role applies
A role is not global. Every grant is attached to one level of the folder tree, and it applies to that level and everything inside it:
- Workspace — the whole account, every client in it.
- Client — one client, every brand and campaign under them.
- Brand — one brand and its campaigns.
- Campaign — a single campaign.
This is what lets an agency give a freelancer write access to one campaign without exposing the rest of the account, or give a client read access to their own brand and nothing else. When someone holds more than one grant, the most permissive one applies.
Teammates and external viewers
Access is granted to one of two kinds of recipient. A teammate is a person with a URLcut.ai account, and they take a seat. An external viewer is granted access by email address and opens a report through a link, with no account and no seat — and that grant can be given an expiry date, after which it stops working on its own.
The Agency plan includes five seats, which is the account owner plus four teammates. A seat is a person with access, so an invitation that has been sent but not yet accepted occupies one until it is accepted or withdrawn. External viewers do not count against the limit.
Frequently asked questions
What are the team roles in URLcut.ai?
URLcut.ai has three roles: read, write and admin. Read views analytics. Write adds creating, editing and deactivating links, managing campaigns and sharing reports. Admin adds deleting links permanently, managing who has access, and renaming or deleting a client, brand or campaign.
Who can delete a link in URLcut.ai?
Only the admin role can delete a link. Deleting is permanent and releases the short code back into the available pool, so anyone could then claim it and inherit traffic from QR codes and emails already in circulation. The write role can deactivate a link instead, which stops it and keeps the short code reserved.
Can I give someone access to only one campaign?
Yes. Every access grant is attached to a workspace, a client, a brand or a campaign, and applies to that level and everything inside it. A freelancer can be given write access to a single campaign without seeing the rest of the account.
Do external viewers use a seat?
No. An external viewer is granted access by email address and opens a report through a link, with no URLcut.ai account and no seat. Only teammates take seats. An external viewer's access can be given an expiry date, after which it stops working automatically.
How many seats are included?
The Agency plan includes five seats, which is the account owner plus four teammates. A seat is a person with access, so an invitation that has been sent but not yet accepted occupies one until it is accepted or withdrawn. External viewers do not count against the seat limit.
More documentation is in the URLcut.ai docs. For what team workspaces are for, see team workspaces.