Access is decided by a role made of module-plus-action permissions, and then narrowed further per agent. There is one built-in role - Admin - and everything else you build yourself.
Admin is the only system role. It has every action on every module and cannot be deleted or demoted - which is what stops a workspace locking itself out. The first person to accept an admin invite activates the workspace and becomes its owner.
There is no Owner or Member role built in
| Module | Covers |
|---|---|
| Agents | Creating, configuring and deleting agents. |
| Conversations & Inbox | The inbox: approving and rejecting replies, reassigning threads, merging leads. |
| Leads | Viewing and editing CRM records. |
| Knowledge Base | The sources the agent answers from. |
| Integrations | Connecting mailboxes, WhatsApp, calendar, phone numbers. |
| Routing Rules | Auto-assignment of inbound conversations. |
| Team | Inviting, removing and re-roling teammates. |
| Roles & Permissions | Creating and editing the roles themselves. |
| Billing & Plans | Credits, invoices and plan changes. |
| Analytics | Workspace reporting. |
| Tasks | Creating, assigning and managing tasks. |
| Campaigns | Building and sending outbound campaigns. |
| Prospects / Outreach | Prospect search and outreach. |
| Action | Meaning |
|---|---|
| read | See it. |
| create | Add new ones. |
| update | Change existing ones. |
| delete | Remove them. |
| assign | Hand work to someone else (tasks). |
| merge | Combine duplicate records (conversations and leads). |
| manage | The catch-all. Granting manage implies every other action on that module - use it for the people who own an area. |
Not every module offers every action - Analytics, for instance, is read or manage.
Roles that tend to earn their keep:
Least privilege is cheap here
Roles are workspace-wide. Agent access narrows them. A member with full conversation permissions can still be blocked from a specific agent's inbox - useful when one agent handles something the whole team shouldn't read.
Access is opt-out: members can use every agent unless you turn one off for them, from the member's row in Members. The block is enforced server-side on the conversation, analytics and playground routes, not just in the UI.
Teams group members for routing and ownership - Sales, Support, Onboarding. A team can have a lead, and both conversations and tasks can belong to a team.
One account, one workspace
409 and the invite is left unused. They need a different email address, or to leave their current workspace first.