Documentation / Team

Team & permissions

A workspace holds your bots, audience, and billing — and the teammates you invite into it. What each person can do is decided by their role, enforced both in the console UI and on every API and server call.

Roles

RoleWhat it can do
OwnerEverything, including billing and deleting the workspace. The first account in the workspace; exactly one owner at a time.
AdminDay-to-day management: publish and delete bots, manage the team and workspace settings. Cannot change billing.
EditorBuild and edit flows, create bots, send broadcasts — the builder's role.
AnalystRead analytics and export audiences; no editing of bots or settings.
ViewerRead-only access for stakeholders.

Roles are ranked — Owner > Admin > Editor > Analyst > Viewer — and each capability has a minimum rank. When the console says a button is unavailable to you, the server rejects the same action with the same reason, so permissions can't be bypassed by calling the API directly.

Permission matrix

ActionMinimum role
Create botsEditor
Edit flows & productsEditor
Send broadcastsEditor
Publish a flow versionAdmin
Delete botsAdmin
Manage team membersAdmin
Workspace settingsAdmin
Export audienceAnalyst
Billing & subscriptionsOwner

Seats and invitations

Every product includes a seat allowance (see the pricing page for the live numbers; the Billing page's Seat meter shows your usage). Inviting a teammate consumes a seat; removing them or ending their membership frees it again.

Invite by email from the console's Team page. The invitee receives a personal link; accepting it creates their account (if they don't have one) with the role you chose. Membership confirmations and renewals are delivered by email with retries — an invitation is never silently lost.

People leave? Remove them from the Team page. Their account loses access to this workspace immediately; anything they built stays with the workspace.

Sign-in security

Email verification. Accounts verify their address before they can pay or receive operational mail — receipts and alerts always reach a real inbox.

Two-step verification. If your platform operator has enabled it, a one-time code is required at sign-in in addition to the password; the operator can also make it mandatory for all accounts. Configure it from your account settings.

Single sign-on (SSO / SAML). Included with the Enterprise line for organisations that manage identity centrally — ask your operator to enable it for the workspace.

Audit trail. Sensitive actions in the workspace (publishing, member changes, plan changes) are recorded with who did what and when; on lines with the audit-log feature the full history is browsable in the console.