Docs

Members, roles & RBAC

How workspace seats, invitations, and role-based access control work.

Roles

RoleCan doCannot do
OWNEREverything — billing, role changes, member removal, branding
ADMINInvite/revoke members, manage automations, API keys, settingsChange billing plan, demote/remove the OWNER
MEMBERCreate + edit workflows, automations, templates, contactsInvite members, manage API keys, change settings
VIEWERRead-only across the workspaceEdit anything

Invitations

ADMIN or OWNER opens Members → Invite, enters the invitee's email + role, and shares the resulting URL. The invite token lasts 14 days; when the invitee clicks the link they set their name + password, which creates a User + boundMembership in one transaction.

Seat caps

Plan caps include pending invitations so a Growth workspace at 10/10 can't queue an 11th. Revoke an unused invite to free the seat immediately.

Last-OWNER protection

You can't demote or remove the last OWNER. Promote another member to OWNER first, then change the previous OWNER's role.