Skip to main content

Roles and permissions

Access is role-based plus optional custom matrices per module (view/create/edit/delete). If a sidebar item is missing, check role first before assuming a bug.

Video

Video coming soon for this topic

Who can do this

Owners/Admins configure; all users should know their role boundaries.

What you'll accomplish

  • Clarity on Settings vs module access
  • Plan to adjust custom role before offboarding users

Step-by-step procedure

Standard roles

RoleTypical access
OwnerEverything including billing, delete workspace, whitelabel
AdminSettings, team, integrations, most modules
ManagerContent creation + wide data read
MemberAssigned work; limited settings

Custom roles

  1. Settings → team → permissions tab (/workspace/users?tab=permissions).
  2. Clone nearest standard role.
  3. Grant least privilege per module.
  4. Save; ask user to refresh browser.

Common modules in matrix

Contacts, Inbox, Deals, Email Campaigns, Calling Campaigns, Smart Flows, AI Employees, Social, Boards, Workforce, Reports Center, Billing, Settings—each with granular flags.

Special cases

  • Action Required visible to owners/admins/workspace owner only.
  • Inbound Call Logs may be hidden via call_logs.view_inbound flag.
  • WhatsApp modules split: whatsapp_chat vs whatsapp_business.

Extended guidance

Document custom roles in HR offboarding checklists—revoke before last day. Managers often need reporting view without billing; clone Manager rather than Admin. Test permission changes with a sandbox user account when possible.

Practice scenarios

Clone Member, grant reporting only, verify Reports Center visible while Settings hidden.

Sandbox validation

Repeat the procedure in a test workspace or with two internal colleagues before customer-facing launches. Document who approved each step (marketing, legal, ops). Screenshot Verify your work outcomes for audit trails. When something fails, capture the URL, role, timestamp, and exact UI label clicked—Support resolves tickets faster with that context. Re-read See also links after your first successful run; adjacent topics often cover edge cases you have not hit yet.

Team rollout checklist

Assign a single owner for this workflow per workspace. Schedule a 30-minute handoff training with screen share. Add the See also links to your internal Notion or wiki. Re-verify after each major product release (labels move occasionally). Pair junior staff with a senior reviewer for the first live execution. Log lessons learned in your team retro—especially permission surprises and integration timeouts.

Keep learning

Bookmark this page and the Product module map. After major releases, re-walk Step-by-step procedure—UI labels move occasionally. Share feedback with your workspace Admin so Help stays aligned with how your team actually works.

Verify your work

  • User sidebar matches expected modules after refresh
  • Member cannot open billing unless intentionally granted
  • Permission change audited in admin logs when enabled

Tips

important

Review custom roles quarterly—feature launches add new permission keys.

Troubleshooting

| Missing Settings | Role lacks settings permission | | Member sees billing | Role too permissive—tighten matrix | | Marketing menus partial | Module disabled in Workspace modules |

See also