Account Roles and Permissions
Table of Contents
DNSimple has two account-level roles and two domain-level roles. Full Access and Limited Access apply to the whole account. Domain Manager and Zone Operator apply to a single domain and are assigned through Domain Access Control.
For how these roles work and why per-domain permissions matter, see What is Domain Access Control?. To assign roles, see Domain Access Control.
Note
Limited Access and the domain-level roles are available on eligible plans. On other plans, every member has Full Access.
Account roles
Account roles apply across the entire account.
Full Access
A member with Full Access can use every resource in the account. This includes all domains, contacts, certificates, templates, billing, and account-level settings. It is the appropriate role for account administrators and trusted team members who manage the account as a whole.
Limited Access
A member with Limited Access can join and see the account but cannot access any domains until you grant permission. For each domain the member needs to work on, you assign either the Domain Manager or Zone Operator role.
Domain roles
Domain roles apply to a single domain and are only available to members with Limited Access.
Domain Manager
For an assigned domain, a Domain Manager can manage the full domain, not only its DNS zone:
- View and manage DNS records.
- Change registration details, including the registrant and name servers.
- Create certificates.
- Enable or disable the DNS service.
- Set up Vanity Name Servers, if available on the account.
A Domain Manager cannot manage billing or account-level settings.
Zone Operator
For an assigned domain, a Zone Operator can manage only the DNS zone:
- View and change DNS records using the Record Editor and One-click Services.
- Import and export zone records.
A Zone Operator cannot change registration details, name servers, certificates, billing, or any setting outside the DNS zone.
Permissions matrix
The account roles apply account-wide. Domain Manager and Zone Operator are not separate account roles. They are domain-level roles you assign to a Limited Access member for specific domains. Those columns show what that member can do on an assigned domain.
| Capability | Full Access | Limited Access | Domain Manager | Zone Operator |
|---|---|---|---|---|
| Sign in and see the account | Yes | Yes | Yes | Yes |
| Manage billing, subscription, and payment | Yes | No | No | No |
| Manage account settings, members, and seats | Yes | No | No | No |
| Access every domain in the account | Yes | No | No | No |
| Manage DNS records for an assigned domain | Yes | No | Yes | Yes |
| Import and export zone records | Yes | No | Yes | Yes |
| Change registration details and name servers | Yes | No | Yes | No |
| Create and manage certificates | Yes | No | Yes | No |
| Enable or disable the DNS service | Yes | No | Yes | No |
| Configure Vanity Name Servers | Yes | No | Yes | No |
Roles in the API
Roles apply to the DNSimple web interface and to user tokens. A member using their user token has the same permissions they have in the interface. A Zone Operator can use their user token to manage DNS records for a permitted domain, but cannot change registration details or billing.
Account tokens are not limited by these roles. An account token has full account access, similar to Full Access, and is intended for account-level automation. See account tokens vs user tokens for details.
Have more questions?
If you have any questions about account roles or permissions, contact our support team, and we’ll be happy to help.