Read-only Site Administrators
A Read-only Site Administrator sees exactly what a Site Administrator can see, nothing less. The distinction is permission to make changes, not visibility. Assigning this role requires a level of trust close to that required for a Site Administrator. It supports troubleshooting, audits, and oversight by people trusted to review the site's configuration and activity.
Administrative Visibility
Any feature, record, or setting visible to a Site Administrator is equally visible to a Read-only Site Administrator. References throughout this documentation to what Site Administrators can view apply equally to this role.
This visibility includes highly sensitive information about other people's work. API request logs, for example, show usernames, request paths, IP addresses, and operation results. Together with configuration and sharing records, that information reveals how people and systems use the site.
Treat the role as access to highly sensitive data, and apply the same care to assignment, account protection, and access reviews as for Site Administrators. Preventing configuration changes does not make the information less confidential. Grant the role only when the person's work requires broad administrative visibility; ordinary folder permissions are appropriate when they only need access to selected files.
Permissions to Make Changes
The Read-only Site Administrator role does not grant permission to change site configuration. Permissions granted separately still authorize their usual actions. For example, a user who also has Folder Admin permission can manage the supported settings of that folder, and a user with Share permission can create Share Links. Assigning the role does not remove permissions the account already holds.
Child Sites
A parent-site user or group can receive Read-only Site Administrator access to a selected Child Site. Within that Child Site, the user sees exactly what its Site Administrators can see, without permission to change its configuration. The grant does not make the user a Parent Site Administrator.
Administrative Permission Levels covers assignment and the related roles. Full Parent Site Administrator authority is different: it includes management of every Child Site and cannot be reduced through Child Site configuration.