Team brings together members, invitations, role assignments and access history. Human permissions control console actions; the assistant has its own separate capability policy.
Open Workspace → Team and use the invitation flow if your account has invite access. Choose the access offered by the form and send the invitation through the available workflow. Pending invitations show their current state and available management actions.
Invitation choices are checked on the server. You cannot use an invitation to grant permissions you do not hold, assign an unavailable role or create ownership implicitly. A teammate completes the invite acceptance flow before using the workspace. A teammate who accepts is never taken through workspace setup: that belongs to the account the workspace was created for, and they go straight to the areas their role opens.
Roles & access lists built-in role presets, custom roles and the permissions they contain. Presets cover workspace administration, support, appointments, orders, content, marketing, assistant configuration, analytics, integrations, privacy and billing.
The Assigned Support Agent preset sees only the customer matters assigned to them — on the console and in the phone app alike. Every other conversation stays out of their queue and cannot be opened by link. A teammate with the assign permission hands a matter to them from the conversation, and their phone is the one that is told.
Inspect a member’s effective permissions and assignment history before changing access. A member can hold multiple assignments, and their effective permissions are the combination of all of them. Existing accounts without assignments keep their legacy role bundle (administrator or agent), so the role system does not silently reset their access.
Once a member has an assignment, their permissions decide what they can reach, whatever their legacy role. Each area of the console, and the API behind it, opens only for the permissions that area needs. A preset opens exactly its areas: a Content Editor reaches Knowledge, Media library and Catalog but not the conversation inbox, and an administrator narrowed to a scoped role loses the areas outside it. The server checks the permission on every request, so removing a role takes effect on the teammate’s next action.
A role definition does not enable a product feature: platform switches, plan entitlements, workspace readiness and sensitive-action requirements still apply.
An area appears in the sidebar when a member holds at least one of its permissions. Inside an area, each action needs its own permission, so a member who can view an area may not be able to change it.
Managing roles requires the relevant team permission. Create a custom role from the available permission vocabulary, then assign it to the appropriate members. Authority changes can require MFA; the service checks what the acting member may grant and protects against removing the last required owner or administrator.
Owner-only permissions cannot be included in a custom role. A permission listed in the registry is not a promise that every related product workflow is exposed on Team. Review the resulting effective access and the access-history entry after a change.
Each teammate manages their own password, MFA and sessions under Account, and can delete their own account there. A deleted teammate shows as Deleted on the Team page and cannot be turned back on; the last owner or administrator of a workspace with teammates hands that role over before deleting. A teammate can also change the address they sign in with, under Account: after re-entering their password, a one-time code goes to the new address, and nothing changes until it is entered; the previous address is told. The workspace’s own name is changed under Account → Workspace by the workspace owner only; other members see it there and who can change it. Sensitive operations may require a current MFA-authenticated session even for an administrator. Team access and shared-channel customer membership are different: customer invitations live under Settings → Customer access.
See the console tour for screen names and security and privacy for data-management controls.