Team & roles
Bring your team in and give everyone exactly the access they need — no more, no less. Seven built-in roles with a fixed permission map cover the common cases, and membership is per workspace so an agency or multi-brand setup stays cleanly separated.
What you'll need
- Owner or admin access to invite members and change roles
The seven roles and what they can do
Reading is open to everyone: any member can see contacts, campaigns, templates, automations, analytics, domains, webhooks and integrations. Roles differ by write access — who can change what.
- Owner — full access to every feature, plus billing and ownership transfer. Owns the workspace.
- Admin — full access to every feature and member management. No billing or ownership transfer.
- Marketer — the full campaign lifecycle: builds and sends campaigns, manages contacts, templates and automations.
- Designer — creates templates and campaign drafts, but cannot send them.
- Analyst — read-only across the whole workspace; changes nothing.
- Developer — sending domains, webhooks, integrations, automation wiring and API keys. Cannot send campaigns or manage members.
- Auditor — read-only plus GDPR data-subject requests (export and erase).
How permissions work
Permissions are written as resource:action — for example contacts:write, campaigns:send or webhooks:write. A role is a fixed set of these; there are no per-person exceptions layered on top.
- Reads (e.g. contacts:read) are open to every member; writes are gated per role.
- Owner and admin hold the full permission set; every other role has its own explicit list.
- API keys are governed by scopes, not roles — programmatic access is configured separately from people.
Manage members
- 1
Open Settings → Members
See members, their roles, MFA status and pending invites.
- 2
Invite by email
Send an invite with the role they should have. Unaccepted invites expire, so stale links don't linger.
- 3
Change a role anytime
Pick a different role from the dropdown next to a member. The last owner can't be demoted or removed, and only an owner can grant the owner role.
Keep accounts secure
- MFA — members can enable two-factor authentication; the list shows who has it on.
- Sessions — active sessions are tracked and can be ended.
- Per-workspace membership — a person added to one workspace has no access to another unless invited there too.
Frequently asked questions
Can I give someone access to just analytics?
Yes — the Analyst role is read-only across the whole workspace, with no write access.
Can I fine-tune permissions for one person?
There are no per-person exceptions — access is defined by the role. Pick the role closest to the access you want, and use API keys with scopes for programmatic access.
Do invites expire?
Yes. Unaccepted invites time out, so an old invite link can't be used later.
Does access carry across workspaces?
No. Membership is per workspace — that's what keeps multi-brand and agency setups isolated.
Start sending in minutes
Create a free account, connect your domain and reach your audience across every channel — no credit card needed.
Free plan forever · No credit card required · Set up in minutes