Project access and spending limits
Restrict a project to specific members, cap what each member can spend, and understand exactly when each rule applies.
Two independent controls sit on top of roles. A role says what someone may do; project access says where they may do it; a spending limit says how much it may cost. All three apply at once, and the strictest one wins.
Both controls on this page are part of advanced access control, which is included in some plans. If your organization is not on one of them you can still see and remove anything already in place — you just cannot add new restrictions. Check Settings → Billing.
Project access
Section titled “Project access”By default every project is open to everyone in the organization. Restricting one is opt-in, per project:
- Open Projects, click the project, then Edit.
- Under Access, tick the people who should have it.
- Save.
From that moment the project — and everything inside it: campaigns, runs, results, alerts, saved searches, chat conversations, files — is invisible to everyone else. Not greyed out: it does not appear in lists, and a direct link returns “not found”.
Untick everyone to re-open the project to the whole organization.
Notes worth knowing
Section titled “Notes worth knowing”- Re-opening is deliberate. Unticking everyone re-opens the project, and both apps confirm before doing so.
- Somebody leaving does not re-open it. If everyone assigned to a project leaves the organization, the project stays restricted with nobody on it — visible only to owners and admins — rather than quietly opening to the whole team. Assign someone, or re-open it on purpose.
- Items outside any project stay visible. A search that was never filed into a project is organization-wide.
- Public campaigns stay public. Someone who cannot see the project still opens a publicly shared campaign in it exactly as an outside visitor would — a teammate never sees less than a stranger with the link.
- API keys, webhooks and scheduled runs are not restricted. They act as the organization, not as
a person. A restricted member with an API key can therefore reach project data through the API —
scope the key, or do not grant
API key: Create. - Leaving the organization removes assignments. Re-inviting the same person does not restore them; assign them again.
Spending limits
Section titled “Spending limits”A limit caps how many tokens one member may spend. It applies to everything that costs tokens — searches, campaign runs, data chat — and is checked before each charge.
Set a default for everyone in Settings → Team → Team info → Spending limits, and override it for one person in Settings → Team → Members → Edit limits.
| Value | Meaning |
|---|---|
| (empty) | No limit |
0 | May not spend at all — the way to freeze one person without changing their roles |
| any number | That many tokens in the period |
An override replaces the default completely. Someone with an override of “no limit” is unlimited even when the organization default is 500 — that is how an owner exempts themselves. Use team default removes the override.
The two periods
Section titled “The two periods”- 24 hours — a rolling window, not a midnight reset. Spending 500 tokens at 23:00 still counts against the limit at 08:00 the next morning. There is no moment when the counter empties, so there is no way to spend twice the limit by straddling midnight.
- 30 days — also rolling. The monthly limit is a trailing 30 days, whatever your plan bills on: tying it to the billing cycle would turn “monthly limit” into “yearly limit” for anyone on an annual plan.
Usage counts what that member actually consumed: charges minus refunds. A refunded run gives the headroom back. Token purchases and plan renewals are never counted as spending.
Notes worth knowing
Section titled “Notes worth knowing”- Limits apply to owners too, if the organization default is set. An owner who does not want one gives themselves an override of “no limit”.
- Scheduled runs are not charged to a person. They belong to the organization, so they consume organization tokens without touching anyone’s limit. A limit is not a way to stop a schedule — pause or delete the campaign instead.
- API-key usage is not charged to a person either, for the same reason.
- Data chat is priced after the answer. A member with a little headroom left can slightly overshoot on one long answer; their next question is refused. The answer is never thrown away after being generated.
- Removing a member deletes their override. Re-inviting them starts from the organization default.
Which control do I want?
Section titled “Which control do I want?”| You want to… | Use |
|---|---|
| Stop someone using a tool at all | A role without that tool |
| Stop someone deleting things | A role without Delete on those subjects |
| Keep a client’s work away from most of the team | Project access on that client’s project |
| Keep one person’s costs bounded | A spending limit |
| Freeze one person’s spending immediately | A spending limit of 0 |
| Stop all spending in the organization | Pause campaigns, or remove tool permissions — a per-member limit will not do it |
Troubleshooting
Section titled “Troubleshooting”“I ticked members on a project and nothing changed.”
The people who still see it hold Project: Read. See the caution above.
“A member says they are blocked but the organization has plenty of tokens.” They have hit their own limit. Settings → Team → Members shows each person’s usage against their limit for both periods.
“Their limit says ‘Default’ but I set one for them.” “Default” means no override — the value shown comes from the organization default. Use Edit limits to give them their own.
“I cannot set a limit or restrict a project.”
Either your plan does not include advanced access control, or you do not hold Member: Update (for
limits) or Project: Update (for access). Removing an existing restriction always works.