People on your account
Inviting others, what each role can do, and how to give access without giving away everything.
More than one person can work on an account. Everyone gets their own login — sharing one is how a departing contractor ends up still having access a year later.
Roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing and closing the account. There is always exactly one. |
| Admin | Runs the account day to day: links, keywords, domains, imports, settings, and inviting people. Cannot touch billing. |
| Editor | Links and keywords. Cannot change settings, domains, or people. |
| Viewer | Reads analytics. Changes nothing. |
Those four cannot be deleted or edited, so an account can never end up in a state where nobody can administer it.
If they do not fit, create a custom role and pick exactly the permissions it should have.
Why Admin cannot do billing
An agency running a client's account should be able to do the work without being able to change the card or cancel the plan. Splitting those is the point of having roles at all.
Inviting somebody
Settings → Members → Invite. They get an email, and they set their own password. If they already have an AffyLink login, that one works.
Removing somebody
Remove them from Members. Their access ends immediately, and everything they created stays — links and keywords belong to the account, not the person.
Any API keys they created are revoked automatically. If one of those keys was connecting a WordPress site, that site stops linking until somebody connects it again with a new key — which is the right way round, because the alternative is a credential still working after you removed the person holding it.
Two-factor authentication
Turn it on in your profile. It uses any authenticator app.
Your account holds the affiliate URLs your income runs through. Somebody who got into it could quietly change a destination to their own affiliate tag, and you would not notice for months — your links would still work, they would just be earning for somebody else. That is the specific attack 2FA is worth defending against here.
Save your recovery codes when you set it up. Each works once.
Something here wrong or unclear? Tell us — we would rather fix the page than answer the same question twice.