Roles and permissions
What Owner, Admin, Agent and Viewer can do, the 10 permissions you can switch on or off per member, and their defaults.
Who can change them: Owner and AdminPlan: All plans
The four roles
| Role | Summary |
|---|---|
| Owner | Full control over the account and billing. One per workspace — the person who created it. |
| Admin | Manages members and everything else. |
| Agent | Uses the features — inbox, contacts, deals, broadcasts — but no settings. |
| Viewer | Read-only across the app. |
Permissions
Each member’s permissions start from their role’s defaults. Owners and admins can switch individual permissions on or off for a member.
| Permission | Allows | Owner | Admin | Agent | Viewer |
|---|---|---|---|---|---|
| WhatsApp connection | View or change the Meta access token, phone number and app credentials | ✓ | ✓ | — | — |
| Message templates | Create, edit and submit templates to Meta | ✓ | ✓ | — | — |
| Automations & flows | Build and activate automations and flows | ✓ | ✓ | — | — |
| Broadcasts | Launch broadcast campaigns | ✓ | ✓ | ✓ | — |
| Team & permissions | Invite or remove members, change roles and permissions | ✓ | ✓ | — | — |
| Billing | View and change the plan and payment details | ✓ | ✓ | — | — |
| API keys & webhooks | Create or revoke API keys and webhooks | ✓ | ✓ | — | — |
| Pipeline settings | Configure pipeline stages (moving deals is always allowed) | ✓ | ✓ | — | — |
| Custom fields & tags | Define custom fields and tags | ✓ | ✓ | — | — |
| View all contacts | See every contact and conversation, not just assigned ones | ✓ | ✓ | ✓ | ✓ |
Permissions are enforced on the server, not just hidden in the menu — a member without a permission can’t use it through the API either.
Common setups
- Sales agent who should only see their own leads — Agent, with View all contacts off. See Contact visibility.
- Marketing person who runs campaigns — Agent, with Message templates and Automations & flows on.
- Manager who watches but doesn’t touch — Viewer.