Contents
What a Client Is
Member Roles
What Each Role Can Actually Do
Inviting a Member
Changing a Member’s Role
Disabling or Removing a Member
What a Client Is
On this platform, your organization’s account is called a Client. Everything under Client
Administration — members, keys, integrations, branding — is scoped to your Client; you won’t see
another organization’s data, and system-wide settings (covered in
System Administration) are managed
separately by system admins, not by Client Admins.
Member Roles
Every member of your Client has exactly one role:
| Role (as shown) | Stored value | Summary |
|---|---|---|
| Readonly | readonly | Sees everything, changes nothing |
| User | user | Runs the event day |
| Client Admin | admin | Configures the client |
| System admin | — | Platform operators, above every client |
Each role can do everything the role before it can. System admins aren’t members of your Client;
they can do everything a Client Admin can, plus a few things reserved for them (see below).
What Each Role Can Actually Do
✓ = allowed, — = not allowed.
| Page / action | Readonly | User | Client Admin | System admin |
|---|---|---|---|---|
| Pages | ||||
| See Events, Clips, Uploads, Stream Keys, Restream Keys, Signage, OBS Plugin | ✓ | ✓ | ✓ | ✓ |
| See YouTube, Slack, Members, Branding | — | — | ✓ | ✓ |
| Event day | ||||
| ▶ Preview the live stream | ✓ | ✓ | ✓ | ✓ |
| See an event’s match list | ✓ | ✓ | ✓ | ✓ |
| Start/Stop Push, Go Live/Stop Broadcast, End preview | — | ✓ | ✓ | ✓ |
| Complete an event; Re-check on the keyframe warning | — | ✓ | ✓ | ✓ |
| Turn signage on or off for an event | — | ✓ | ✓ | ✓ |
| Reopen a completed event | — | — | ✓ | ✓ |
| Event setup | ||||
| Configure/Unconfigure an event, edit its settings (Basics, Stream window, Livestream, Blue Alliance) | — | — | ✓ | ✓ |
| Change an event’s Timezone | — | — | — | ✓ |
| Broadcast days | ||||
| Add a day, Create/Replace a broadcast, Remove a day | — | ✓ | ✓ | ✓ |
| Create or delete the setup-day test video | — | ✓ | ✓ | ✓ |
| Delete a replaced broadcast on YouTube | — | — | ✓ | ✓ |
| Clips and uploads | ||||
| Approve, discard or requeue a clip; requeue an upload | — | ✓ | ✓ | ✓ |
| Archive or delete a clip | — | — | ✓ | ✓ |
| Keys | ||||
| Reveal/Copy a stream key | — | ✓ | ✓ | ✓ |
| Add, disable, rotate or delete a stream key | — | — | — | ✓ |
| Reveal/Copy, add, rotate or delete a restream key | — | — | ✓ | ✓ |
| Signage | ||||
| View signs and their status | ✓ | ✓ | ✓ | ✓ |
| Switch a sign’s display, refresh, re-apply, send screen commands | — | ✓ | ✓ | ✓ |
| Assign a sign to a stream key; connect or unlink the AbleSign API key | — | — | ✓ | ✓ |
| OBS plugin | ||||
| Download the plugin | ✓ | ✓ | ✓ | ✓ |
| Pair and revoke devices | — | — | ✓ | ✓ |
| Client settings | ||||
| Members, YouTube, Slack, Branding | — | — | ✓ | ✓ |
Stream keys are managed by system admins; see
Stream Keys and Restream Keys.
When a Control Is Disabled
Controls are never hidden by role on these pages. A control you can’t use right now is drawn at
half opacity, and it tells you why:
- Hover over it to see the reason in a tooltip.
- Click or tap it to see the reason as a pop-up message.
- Primary buttons (such as Start Push) also show the reason on a small line underneath.
A reason that starts with 🔒 is a role or policy limit, and it won’t clear by itself:
- ”🔒 Needs User or above”
- ”🔒 Needs Client Admin”
- ”🔒 Turned off by system administrators”
- ”🔒 Set by system administrators”
A reason without 🔒 describes the current state (for example “Wait for the push to stop”) and clears
by itself once that state changes.
On forms, a 🔒 next to a field’s label means that field is locked; hover over it (or tap it) to see
why. A whole section you can’t edit shows one 🔒 line under its title, such as ”🔒 Needs Client
Admin”, and its Save button is dimmed. If the page doesn’t yet know whether an action is
allowed (for example while it’s still loading), the reason reads “Not available right now”.
What’s Hidden From Client Roles
A few details are kept to system admins, whatever your Client role:
- Clip and upload errors are shown to Client members as one of a fixed set of plain-language
reasons, such as “Shorter than the scheduled match; check before approving”, “Clip processing
failed” or “The YouTube channel needs to be reconnected”. The raw error is for system admins.
The full lists, and what to do about each, are in
Clips, Uploads and Signage. - Internal storage paths and worker names are shown to system admins only.
- A Readonly member doesn’t see the incoming stream’s publisher IP address, and sees “The push
failed” instead of the push’s detailed error. - An event’s Blue Alliance auth secret is never shown back once saved, to anyone.
Reopen appears only on completed events. There’s no manual control for an event stuck live or in
progress: it heals by itself, and one left in progress after its stream window completes itself
(see Event Auto-Complete).
Inviting a Member
- As a Client Admin, open Members in the dashboard.
- Click + Invite Member.
- Fill in the Email address field (this is only used to identify the member — no invitation
email is actually sent by the platform) and choose a Role from the dropdown: “Client Admin —
full access: configures events, manages members and keys”, “User — runs the event day: clips,
broadcasts, restream; cannot configure events”, or “Readonly — view only”. - Click Send Invite. If someone with that address is already a member, you’ll see “A member
with this email already exists”. - The panel switches to Invite Link and shows the link under “Share this invite link with the
new member:”, with a Copy Link button. Copy it and send it directly to that one person — a
1:1 message or an email to them alone, never a shared/public channel, a ticket, or a shared doc —
the platform does not email it for you. Treat the link like a password while it’s in transit.
Click Done when finished. - The new member appears immediately in the Members table with a yellow Pending badge. If you
need the link again later, a small Copy invite button appears next to their name (for Client
Admins and system admins only) while the invite is still open.
The link only works when the person signs in with the Google account for the invited address, so it
isn’t usable by anyone else even if it leaks — but still don’t treat that as license to share it
loosely.
Invite links expire after 7 days, and an expired link can’t be used. A pending member whose invite
has expired shows a red Invite expired badge instead of Pending (hover for “Use Re-send
invite to send a new link”), and Copy invite no longer appears.
Re-sending an Invite
Every pending member who isn’t disabled has a Re-send invite button next to their badge. It
issues a new link for the same address and role and closes the old one:
- For an expired invite it sends straight away.
- For a still-valid invite it asks first: “Re-send invite to email?” / “The current invite link
will stop working.” Click Re-send.
A New invite link dialog shows the link (“Copy it from the Copy invite button or here.”). Send
it to that one person the same way as a first invite. Use this too if a link went to the wrong
person or you’re unsure it stayed private: the old link stops working as soon as the new one is
issued.
Re-sending is refused with “This member has already joined” once they’ve signed in, and with
“Enable this member before re-sending their invite” for a disabled pending member.
If the Invitee Can’t Sign In
The sign-in page explains what went wrong; the full list of messages is in
Getting Started. What to do
for the common ones:
- “This invitation has expired or has already been used. Ask your administrator to send you a new
invite.” — click Re-send invite on their row. - “This invite was sent to a different address. …” — they signed in with a different Google account
from the one you invited. Have them sign in with the Google account for the invited address, or
delete the pending member and invite the address they actually use. - “This address has more than one pending invitation. Ask an administrator to remove the one you
don’t need.” — remove the extra pending entry for that address, then have them sign in again. - “No account found for your Google identity. …” — there’s no member for that Google account. Check
the address you invited matches the account they’re signing in with.
Changing a Member’s Role
Each row in the Members table has an inline role dropdown (Client Admin, User,
Readonly). Pick a new role and confirm the dialog, which names the role by its stored value
(readonly, user or admin):
Change name’s role to “role”?
Their permissions change straight away.
Click Change role to apply it. You can’t change your own role from this control — it’s disabled
on your own row. The platform also won’t demote the Client’s last active Client Admin; the change
is refused with “Cannot remove last admin”. If you need to step down as the only Client Admin,
promote someone else to Client Admin first, and have them sign in.
Disabling or Removing a Member
- Disable (button per row) turns off a member’s ability to log in without deleting their
account or history. The confirmation reads “Disable name?” / “They will no longer be able to log
in.” Click Enable on the same row later to restore access (“Enable name?” / “They will be
able to log in again.”).
Disabling the Client’s last active Client Admin is refused with “Cannot disable the last admin”. - Delete permanently removes their login access. The confirmation reads “Delete name?” / “This
will permanently remove their login access.” Deleting the Client’s last active Client Admin is
refused with “Cannot delete the last admin”. Deleting a pending member also closes their open
invitations, so a link already sent to them stops working. - Both buttons are disabled on your own row (“You cannot disable your own account”, “You cannot
delete your own account”).
For these rules, an active Client Admin is one who is enabled and has signed in at least once. A
pending Client Admin doesn’t count: they can’t do anything until they accept their invite. To hand
over to a new Client Admin, wait until they’ve signed in before another Client Admin is disabled or
removed. System admins aren’t held to these rules.
Keep Two Client Admins
Keep at least two active Client Admins on your Client. If the only one leaves or loses access to
their Google account, nobody can manage the Client’s members or settings until a system admin
steps in.