Roles & permissions
Four roles.Checked on every request.
Owners, admins, members and viewers, each with a fixed set of abilities. Pick one below and see what changes.
As member, you can
- Read conversations, customers and reports
- Reply to customers and edit records
- Write articles and saved replies
- Invite teammates and change roles
- Configure the workspace
- Manage billing, delete the workspace
Settings
MMayamember
Diego AlvarezOur finance lead needs to see invoices but shouldn’t touch settings. What role should she get?
Viewers can read conversations, customers and reports, but can’t reply or change anything.
Give her the Viewer role: she’ll see everything and change nothing.
The matrix
Who can do what, in one table
The same table your admins see in Settings → Access. No hidden exceptions, no per-person overrides to keep track of.
| Capability | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| Everyday work | ||||
| View conversations, customers & reports | ||||
| Reply to customers & edit records | ||||
| Manage knowledge base & saved replies | ||||
| Running the workspace | ||||
| Invite teammates & change roles | ||||
| Configure workspace settings | ||||
| API keys & webhooks | ||||
| Ownership | ||||
| Manage billing & plan | ||||
| Delete the workspace | ||||
Enforced below the interface
Hiding a button isn't a permission
The dashboard hides what you can't do. Behind it, the API checks your role and the database refuses what your role doesn't allow.
ViewerReply to a customer
Read-only by database policy
MemberChange workspace settings
Owner and admin only, by policy
MemberCreate an API key
Role checked by the API
AnyoneRead another workspace
Returns nothing: not your workspace
AdminInvite a teammate
Allowed
ViewerOpen the reports
Allowed
Accounts
Sign-ins you can lock down
Roles decide what someone can do. These decide who gets in as them.
Two-factor sign-in
Scan a code with any authenticator app. From then on, every sign-in asks for a one-time code.
Enter the 6-digit code
From your authenticator app
Sign out everywhere else
Lost a laptop, or left a session open? End every session except the one you’re on.
This browserstays signed in
Every other sessionsigned out
Invite with a role
People join with the role you chose. Only owners and admins can invite or change roles.
- Four fixed roles, easy to reason about
- Teams to group people together
- Workspaces isolated from each other
Roles questions
Admins run the workspace: settings, teammates, roles, integrations, API keys. Only owners manage billing and can delete the workspace.
Still curious? Email hello@kuvra.dev