Roles, permissions, and tier capabilities
What Viewers, Editors, Admins, and Owners can do, how permission groups fine-tune access, and how agency sub-account roles and tiers work.
Every person in a workspace has a role that decides what they can see and change. Admins can fine-tune access further with permission groups. This page explains each role, what it allows, and how to give someone the right access. It's for workspace owners, admins, and agency owners.
How access works
Access is decided in layers. Each layer can only narrow what the one before allows:
- Role: the person's general level (Viewer, Editor, Admin, or Owner).
- Permission groups and individual settings: module-by-module access set by an admin.
- Plan or agency tier: which features the workspace or client account includes.
- The other app: a connected app, such as Google or Meta, still applies its own permissions.
Workspace roles
From least to most access: Viewer → Editor → Admin → Owner.
| Role | What they can do |
|---|---|
| Viewer | See the modules the workspace shares with them. They can't create, edit, or delete. |
| Editor | Everything a Viewer can, plus create, edit, and delete content in enabled modules. |
| Admin | Everything an Editor can, plus manage members, invitations, permissions, workspace settings, and integrations. |
| Owner | Everything an Admin can, plus owner-only actions such as transferring ownership. There's one Owner per workspace, and the Owner's access can't be restricted. |
These are general rules. Some pages have extra checks, and connected apps can still refuse an action.
Who can do what
| Task | Who can do it |
|---|---|
| Invite, remove, or change members' roles | Admin, Owner |
| Create permission groups or individual overrides | Admin, Owner |
| Transfer ownership | Owner |
| Connect, reconnect, test, or disconnect integrations | Admin, Owner |
| Reveal a hidden webhook address | Admin, Owner |
| Create or revoke AI agent access tokens (Settings → AI Agents) | Admin, Owner |
| Connect, run, undo, or finalize a GoHighLevel or HubSpot migration | Admin, Owner (others can view) |
| Connect or test Zoom and Google Meet for webinars | Editor, Admin, Owner |
| Import CRM records | Editor, Admin, Owner |
| Start Email Verifier checks | People with edit access to Email |
| See Email Verifier credit usage | People with view access to Billing |
| Prepare US texting registration | Editor or higher |
| Pay for and submit US texting registration | An admin with messaging management access |
| Manage the plan, payment methods, and top-ups | Usually the Owner or an Admin |
An AI assistant connected with an access token acts as the person who created the token, but never above Editor. See connect AI assistants with MCP.
Manage members and roles
- Go to Settings → Workspace.
- Choose Members to see everyone in the workspace.
- To add someone, select Invite Member. Track pending invites under Invitations.
- To change a role, open the member's actions and choose Change to Admin, Change to Editor, or Change to Viewer.
- To remove someone, choose Remove Member.
You can't change your own role or the Owner's role.
Transfer ownership
The Owner can choose Transfer Ownership for another member. Spacebrain emails them an invitation. Nothing changes until they accept. When they do, they become the Owner, billing moves to them, and the previous Owner becomes an Admin. You can cancel the invitation before it's accepted.
Fine-tune access with permission groups
Roles apply to the whole workspace. Permission groups let you give a set of people different access to specific modules. For example, a sales team could have edit access to the CRM but no access to billing.
- Go to Settings → Workspace → Permissions.
- Under Permission groups, select New group, or select Add starter groups to begin with ready-made ones.
- Enter a Name and Description.
- For each module, choose an access level: none, view, edit, or manage. Full control (manage) stays limited to admins.
- Select Save.
- In the people list, use Add to group… to add people.
A group overrides a person's role for the modules it names. To set one person's access directly, open their access settings and choose Set individually. Individual settings override groups. Select Clear individual settings to return them to their groups and role.
The Effective access column shows what each person can actually do after their role, groups, and individual settings are combined. Deleting a group removes its access from its members straight away.
Only workspace admins and the Owner can change permissions. Others see Only workspace admins and the owner can change permissions.
Agency client sub-account roles
In a client sub-account managed by an agency, roles are Member → Editor → Admin.
| Role | What they can do |
|---|---|
| Member | View the main records the sub-account shares with them. |
| Editor | Work in enabled areas such as CRM, voice, and email, without billing or team management. |
| Admin | Run the sub-account, including billing and team management where the agency's billing setup allows it. |
Spacebrain won't let you remove or demote the only Admin of a sub-account. Promote someone else first, so the account is never left without an admin.
Agency tiers control features
Each client sub-account is on a tier chosen by the agency. The tier decides which features the client gets, such as CRM, Inbox, automations, sequences, enrichment, email sending, phone numbers, AI chat, and building agents.
A higher role doesn't turn on a feature the tier leaves off. If a client needs a feature, the agency changes the tier's features. Both the tier and the role must allow an action.
Connected apps have their own permissions
Being an Admin in Spacebrain doesn't make you an admin in Google, Meta, Stripe, or your domain registrar. A connection can show Connected while an action fails because the connected account lacks the right access in that app.
Give the least access that works
- Think about what the person actually needs to do.
- Give the lowest role that allows it.
- Use permission groups to narrow access to specific modules.
- For clients, turn on only the tier features they've paid for.
- Connect apps using accounts your organization controls.
- Ask the person to try one real task.
- Review access when people change jobs, leave, or after a security incident.
Give everyone their own login. Shared logins make it impossible to see who did what, and hard to remove access later.
A menu or button is missing
Check in this order:
- You're signed in as yourself.
- You're in the right workspace or sub-account.
- Your role.
- Your permission groups and individual settings (see Effective access).
- The sub-account's tier.
- The plan, trial, region, or rollout.
- Any required connection or setup.
- Your permissions in the connected app.
After a role change, save your work, refresh, or sign out and back in. If access is still wrong, send your admin or support the workspace, your role, what you tried to do, the time, and the exact message.
FAQ
Should every team lead be an Admin?
No. Admin is for people who manage members, settings, or integrations. An Editor can do day-to-day work. Use permission groups if a lead needs more access to one module only.
Can an agency owner work inside a client's account?
Yes, through the agency's client access controls. Check you're in the right client account before making changes. Never ask a client for their password.
Can a tier turn on a feature for a Member?
The tier makes the feature available in the sub-account, but a Member may still only be able to view it. Both must allow the action.
Next step
See why features can differ between accounts in feature availability.
Next step
Keep moving
Open the relevant Spacebrain screen or contact support if you need help.
Last updated on
Spacebrain reference
Look up roles and permissions, plan and feature availability, trust resources, Spacebrain terms, product changes, status, and support.
Feature availability
Why menus, apps, and buttons can differ between accounts, how plans affect what you see, and what to do when a feature is missing.