Skip to content
Guides

Give teammates access to their work

Team brings together members, invitations, role assignments and access history. Human permissions control console actions; the assistant has its own separate capability policy.

Invite a teammate

Open Workspace → Team and use the invitation flow if your account has invite access. Choose the access offered by the form and send the invitation through the available workflow. Pending invitations show their current state and available management actions.

Invitation choices are checked on the server. You cannot use an invitation to grant permissions you do not hold, assign an unavailable role or create ownership implicitly. A teammate completes the invite acceptance flow before using the workspace. A teammate who accepts is never taken through workspace setup: that belongs to the account the workspace was created for, and they go straight to the areas their role opens.

Roles and effective access

Roles & access lists built-in role presets, custom roles and the permissions they contain. Presets cover workspace administration, support, appointments, orders, content, marketing, assistant configuration, analytics, integrations, privacy and billing.

The Assigned Support Agent preset sees only the customer matters assigned to them — on the console and in the phone app alike. Every other conversation stays out of their queue and cannot be opened by link. A teammate with the assign permission hands a matter to them from the conversation, and their phone is the one that is told.

Inspect a member’s effective permissions and assignment history before changing access. A member can hold multiple assignments, and their effective permissions are the combination of all of them. Existing accounts without assignments keep their legacy role bundle (administrator or agent), so the role system does not silently reset their access.

Once a member has an assignment, their permissions decide what they can reach, whatever their legacy role. Each area of the console, and the API behind it, opens only for the permissions that area needs. A preset opens exactly its areas: a Content Editor reaches Knowledge, Media library and Catalog but not the conversation inbox, and an administrator narrowed to a scoped role loses the areas outside it. The server checks the permission on every request, so removing a role takes effect on the teammate’s next action.

A role definition does not enable a product feature: platform switches, plan entitlements, workspace readiness and sensitive-action requirements still apply.

What each permission opens

An area appears in the sidebar when a member holds at least one of its permissions. Inside an area, each action needs its own permission, so a member who can view an area may not be able to change it.

Overview, AnalyticsView conversations or view analytics. Overview cards appear only for areas the member can open.
Needs attention, ConversationsView conversations, or view only assigned conversations. Replying needs reply to conversations; taking over, returning and resolving need take over conversations; handing a matter to a teammate needs assign conversations.
ComplaintsView complaints. Deciding or correcting a case needs manage complaints.
Assistant, Capabilities, SetupConfigure the assistant or activate assistant changes. Editing settings needs configure; approving, activating, adopting and rolling back need activate.
Content HomeAny Knowledge, Media library or Catalog permission.
KnowledgeEdit or publish knowledge. Uploading and editing needs edit; review decisions need publish.
Media libraryEdit or publish media. Uploading and organizing needs edit; review decisions need publish.
CatalogManage the catalog.
Smart UpdatesDraft, approve or send Smart Updates. Writing needs draft, approving or stopping an update needs approve, turning sending on or off needs send.
Customer requests, Orders to approveView orders. Changing a request or recording a decision needs approve orders.
AppointmentsView appointments. Confirming, declining and rescheduling need manage appointments; Booking setup needs configure appointments.
SettingsManage integrations (Channels & routing, Web widget, Customer access) or manage team members (Escalation alerts). Each tab opens for its own permission.
TeamInvite teammates, manage team members or manage roles. Sending invitations needs invite; changing members needs manage members; changing roles needs manage roles.
Demo linksManage integrations.
DevelopersManage API credentials (keys and webhooks) or manage integrations (order lookups).
Plan & usageManage billing or view analytics. The subscription, payment and credit panels need manage billing.
PrivacyExport customer data, delete customer data or view the audit log. Each tool needs its own permission.
AccountEvery signed-in member. It holds their own password, MFA and sessions.

Change access

Managing roles requires the relevant team permission. Create a custom role from the available permission vocabulary, then assign it to the appropriate members. Authority changes can require MFA; the service checks what the acting member may grant and protects against removing the last required owner or administrator.

Owner-only permissions cannot be included in a custom role. A permission listed in the registry is not a promise that every related product workflow is exposed on Team. Review the resulting effective access and the access-history entry after a change.

Account security

Each teammate manages their own password, MFA and sessions under Account, and can delete their own account there. A deleted teammate shows as Deleted on the Team page and cannot be turned back on; the last owner or administrator of a workspace with teammates hands that role over before deleting. A teammate can also change the address they sign in with, under Account: after re-entering their password, a one-time code goes to the new address, and nothing changes until it is entered; the previous address is told. The workspace’s own name is changed under Account → Workspace by the workspace owner only; other members see it there and who can change it. Sensitive operations may require a current MFA-authenticated session even for an administrator. Team access and shared-channel customer membership are different: customer invitations live under Settings → Customer access.

See the console tour for screen names and security and privacy for data-management controls.