Developer docs
Permissions
Who can do what in Pagerly — three tiers, the same on Slack, the dashboard and the MCP server.
Three tiers, fixed. There is deliberately no per-workspace permission builder: three roles is what most teams need, and a configurable matrix is mostly a way to lock yourself out.
| Tier | Who | How it is set |
|---|---|---|
| Everyone | any member of the Slack workspace | — |
| Team admin | people on a team’s access list | Slack: the team’s Edit → Setup Access Control. Dashboard: Teams → the team → Users with access to manage the rotation |
| Org admin | the workspace’s named admins, plus the person who installed Pagerly and Slack workspace admins as a safety net | Dashboard → Organisation → Admins |
Both lists are opt-in. A team with no access list is open — anyone can edit it or take over its on-call. A workspace that has named no admins is unrestricted. Nothing changes for you until you set one.
What each tier can do
| Action | Everyone | Team admin | Org admin |
|---|---|---|---|
| Read schedules, teams, incidents, status page | ✅ | ✅ | ✅ |
| Declare and update incidents, action items, status-page updates | ✅ | ✅ | ✅ |
| Override, swap, or remove an override | open teams | ✅ | ✅ |
| Edit a team’s rotation — roster, handover, timezone, user group | open teams | ✅ | ✅ |
| Edit a team’s settings — name, channel, manager, integrations | open teams | ✅ | ✅ |
| Set or remove a team’s shift reminder | open teams | ✅ | ✅ |
| Manage the team’s own access list | open teams | ✅ | ✅ |
| Create a team | — | — | ✅ |
| Delete a team | — | — | ✅ |
| Add, edit or remove people in the on-call directory | — | — | ✅ |
| Escalation policies, integrations, API keys, admins, billing | — | — | ✅ |
In one line: a team admin can do everything scoped to their team except create or delete it; an org admin can do that for every team, plus anything workspace-wide.
The same rule everywhere
One check answers on every surface, so the answer can’t drift between them:
- Dashboard — refuses with the reason.
- Slack — the Override button, the team editor and the assistant refuse with the reason, inline or in a DM.
- MCP — the tool returns
ERROR: …with the reason. Org-admin tools additionally need themcp:adminscope on the connection.
A refused person is always told which team and who to ask:
Only the people who manage Payments can change who is on call. Ask them or alice@example.com.
Deliberately open
Incidents, action items and status-page updates are responder actions: whoever is paged must be able to act without asking. Cover requests are requests, not changes.
Updated 11 September 2026
Put your on-call where your team already is.
Install in two minutes. Import your existing schedule. Page someone tonight.
