Roles and Permissions
Every member of a workspace holds one of three roles. You set it when you invite them, and you can change it afterwards on the Team tab.
| Role | In one line |
|---|---|
| Owner | Pays for the workspace, and the only role that can give it away or delete it |
| Admin | Runs the product day to day: builds bots, connects channels, manages the team |
| Viewer | Reads leads and conversations |
A workspace has one owner. Changing who that is means transferring the workspace, which also moves the bill.
What Each Role Can Do#
| Owner | Admin | Viewer | |
|---|---|---|---|
| See the dashboard and analytics | Yes | Yes | Yes |
| Read leads and conversations | Yes | Yes | Yes |
| Export leads and conversation transcripts | Yes | Yes | Yes |
| Create and edit bots and workflows | Yes | Yes | No |
| Connect and disconnect channels | Yes | Yes | No |
| Create and apply tags | Yes | Yes | No |
| Set the workspace logo | Yes | Yes | No |
| Invite, remove and re-role members | Yes | Yes | No |
| Read the activity log | Yes | Yes | No |
| Erase a contact on request | Yes | Yes | No |
| Set retention windows | Yes | No | No |
| See and manage billing | Yes | No | No |
| Create a client workspace | Yes | No | No |
| Move a bot to another workspace | Yes | No | No |
| Transfer the workspace | Yes | No | No |
| Delete the workspace | Yes | No | No |
Three Rows to Check Before You Invite Anyone#
A viewer can export leads, and the export is recorded. Every role that can read leads can download them as a CSV, and every download of the full set writes an entry to the activity log naming who exported, from which bot, and how many leads. Give somebody Viewer expecting read-only and they can still take the list off the platform.
An admin can erase a contact and cannot delete the workspace. A request to have data removed has a legal clock on it, so it does not wait for the person who pays the bill. Deletion destroys the key the workspace's files are encrypted with, so it stays with the owner.
Moving a bot needs the owner of both workspaces. An admin on the receiving side cannot pull a bot into a workspace whose owner never agreed to hold it.
Limit a Viewer to Certain Bots#
A viewer can be limited to a subset of the bots in a workspace. They see those bots, their leads and their conversations, and the rest of the workspace does not appear for them.
Set it on the Team tab. Invite your team has the steps for an invitation and for a member already in the workspace.
Bot access is the smallest unit a permission covers. Permissions are not set per workflow or per field.