Skip to main content
Spacebrain Help

Roles, permissions, and tier capabilities

What Viewers, Editors, Admins, and Owners can do, how permission groups fine-tune access, and how agency sub-account roles and tiers work.

Every person in a workspace has a role that decides what they can see and change. Admins can fine-tune access further with permission groups. This page explains each role, what it allows, and how to give someone the right access. It's for workspace owners, admins, and agency owners.

How access works

Access is decided in layers. Each layer can only narrow what the one before allows:

  1. Role: the person's general level (Viewer, Editor, Admin, or Owner).
  2. Permission groups and individual settings: module-by-module access set by an admin.
  3. Plan or agency tier: which features the workspace or client account includes.
  4. The other app: a connected app, such as Google or Meta, still applies its own permissions.

Workspace roles

From least to most access: Viewer → Editor → Admin → Owner.

RoleWhat they can do
ViewerSee the modules the workspace shares with them. They can't create, edit, or delete.
EditorEverything a Viewer can, plus create, edit, and delete content in enabled modules.
AdminEverything an Editor can, plus manage members, invitations, permissions, workspace settings, and integrations.
OwnerEverything an Admin can, plus owner-only actions such as transferring ownership. There's one Owner per workspace, and the Owner's access can't be restricted.

These are general rules. Some pages have extra checks, and connected apps can still refuse an action.

Who can do what

TaskWho can do it
Invite, remove, or change members' rolesAdmin, Owner
Create permission groups or individual overridesAdmin, Owner
Transfer ownershipOwner
Connect, reconnect, test, or disconnect integrationsAdmin, Owner
Reveal a hidden webhook addressAdmin, Owner
Create or revoke AI agent access tokens (Settings → AI Agents)Admin, Owner
Connect, run, undo, or finalize a GoHighLevel or HubSpot migrationAdmin, Owner (others can view)
Connect or test Zoom and Google Meet for webinarsEditor, Admin, Owner
Import CRM recordsEditor, Admin, Owner
Start Email Verifier checksPeople with edit access to Email
See Email Verifier credit usagePeople with view access to Billing
Prepare US texting registrationEditor or higher
Pay for and submit US texting registrationAn admin with messaging management access
Manage the plan, payment methods, and top-upsUsually the Owner or an Admin

An AI assistant connected with an access token acts as the person who created the token, but never above Editor. See connect AI assistants with MCP.

Manage members and roles

  1. Go to Settings → Workspace.
  2. Choose Members to see everyone in the workspace.
  3. To add someone, select Invite Member. Track pending invites under Invitations.
  4. To change a role, open the member's actions and choose Change to Admin, Change to Editor, or Change to Viewer.
  5. To remove someone, choose Remove Member.

You can't change your own role or the Owner's role.

Transfer ownership

The Owner can choose Transfer Ownership for another member. Spacebrain emails them an invitation. Nothing changes until they accept. When they do, they become the Owner, billing moves to them, and the previous Owner becomes an Admin. You can cancel the invitation before it's accepted.

Fine-tune access with permission groups

Roles apply to the whole workspace. Permission groups let you give a set of people different access to specific modules. For example, a sales team could have edit access to the CRM but no access to billing.

  1. Go to Settings → Workspace → Permissions.
  2. Under Permission groups, select New group, or select Add starter groups to begin with ready-made ones.
  3. Enter a Name and Description.
  4. For each module, choose an access level: none, view, edit, or manage. Full control (manage) stays limited to admins.
  5. Select Save.
  6. In the people list, use Add to group… to add people.

A group overrides a person's role for the modules it names. To set one person's access directly, open their access settings and choose Set individually. Individual settings override groups. Select Clear individual settings to return them to their groups and role.

The Effective access column shows what each person can actually do after their role, groups, and individual settings are combined. Deleting a group removes its access from its members straight away.

Only workspace admins and the Owner can change permissions. Others see Only workspace admins and the owner can change permissions.

Agency client sub-account roles

In a client sub-account managed by an agency, roles are Member → Editor → Admin.

RoleWhat they can do
MemberView the main records the sub-account shares with them.
EditorWork in enabled areas such as CRM, voice, and email, without billing or team management.
AdminRun the sub-account, including billing and team management where the agency's billing setup allows it.

Spacebrain won't let you remove or demote the only Admin of a sub-account. Promote someone else first, so the account is never left without an admin.

Agency tiers control features

Each client sub-account is on a tier chosen by the agency. The tier decides which features the client gets, such as CRM, Inbox, automations, sequences, enrichment, email sending, phone numbers, AI chat, and building agents.

A higher role doesn't turn on a feature the tier leaves off. If a client needs a feature, the agency changes the tier's features. Both the tier and the role must allow an action.

Connected apps have their own permissions

Being an Admin in Spacebrain doesn't make you an admin in Google, Meta, Stripe, or your domain registrar. A connection can show Connected while an action fails because the connected account lacks the right access in that app.

Give the least access that works

  1. Think about what the person actually needs to do.
  2. Give the lowest role that allows it.
  3. Use permission groups to narrow access to specific modules.
  4. For clients, turn on only the tier features they've paid for.
  5. Connect apps using accounts your organization controls.
  6. Ask the person to try one real task.
  7. Review access when people change jobs, leave, or after a security incident.

Give everyone their own login. Shared logins make it impossible to see who did what, and hard to remove access later.

A menu or button is missing

Check in this order:

  1. You're signed in as yourself.
  2. You're in the right workspace or sub-account.
  3. Your role.
  4. Your permission groups and individual settings (see Effective access).
  5. The sub-account's tier.
  6. The plan, trial, region, or rollout.
  7. Any required connection or setup.
  8. Your permissions in the connected app.

After a role change, save your work, refresh, or sign out and back in. If access is still wrong, send your admin or support the workspace, your role, what you tried to do, the time, and the exact message.

FAQ

Should every team lead be an Admin?

No. Admin is for people who manage members, settings, or integrations. An Editor can do day-to-day work. Use permission groups if a lead needs more access to one module only.

Can an agency owner work inside a client's account?

Yes, through the agency's client access controls. Check you're in the right client account before making changes. Never ask a client for their password.

Can a tier turn on a feature for a Member?

The tier makes the feature available in the sub-account, but a Member may still only be able to view it. Both must allow the action.

Next step

See why features can differ between accounts in feature availability.

Next step

Keep moving

Open the relevant Spacebrain screen or contact support if you need help.

Last updated on

On this page