Skip to content
Platform & team

Team & roles

Bring your team in and give everyone exactly the access they need — no more, no less. Seven built-in roles with a fixed permission map cover the common cases, and membership is per workspace so an agency or multi-brand setup stays cleanly separated.

5 min read

What you'll need

  • Owner or admin access to invite members and change roles

The seven roles and what they can do

Reading is open to everyone: any member can see contacts, campaigns, templates, automations, analytics, domains, webhooks and integrations. Roles differ by write access — who can change what.

  • Owner — full access to every feature, plus billing and ownership transfer. Owns the workspace.
  • Admin — full access to every feature and member management. No billing or ownership transfer.
  • Marketer — the full campaign lifecycle: builds and sends campaigns, manages contacts, templates and automations.
  • Designer — creates templates and campaign drafts, but cannot send them.
  • Analyst — read-only across the whole workspace; changes nothing.
  • Developer — sending domains, webhooks, integrations, automation wiring and API keys. Cannot send campaigns or manage members.
  • Auditor — read-only plus GDPR data-subject requests (export and erase).

How permissions work

Permissions are written as resource:action — for example contacts:write, campaigns:send or webhooks:write. A role is a fixed set of these; there are no per-person exceptions layered on top.

  • Reads (e.g. contacts:read) are open to every member; writes are gated per role.
  • Owner and admin hold the full permission set; every other role has its own explicit list.
  • API keys are governed by scopes, not roles — programmatic access is configured separately from people.

Manage members

  1. 1

    Open Settings → Members

    See members, their roles, MFA status and pending invites.

  2. 2

    Invite by email

    Send an invite with the role they should have. Unaccepted invites expire, so stale links don't linger.

  3. 3

    Change a role anytime

    Pick a different role from the dropdown next to a member. The last owner can't be demoted or removed, and only an owner can grant the owner role.

Keep accounts secure

  • MFA — members can enable two-factor authentication; the list shows who has it on.
  • Sessions — active sessions are tracked and can be ended.
  • Per-workspace membership — a person added to one workspace has no access to another unless invited there too.

Frequently asked questions

Can I give someone access to just analytics?

Yes — the Analyst role is read-only across the whole workspace, with no write access.

Can I fine-tune permissions for one person?

There are no per-person exceptions — access is defined by the role. Pick the role closest to the access you want, and use API keys with scopes for programmatic access.

Do invites expire?

Yes. Unaccepted invites time out, so an old invite link can't be used later.

Does access carry across workspaces?

No. Membership is per workspace — that's what keeps multi-brand and agency setups isolated.

Start sending in minutes

Create a free account, connect your domain and reach your audience across every channel — no credit card needed.

Free plan forever · No credit card required · Set up in minutes

Team roles, permissions, invites & MFA — Climails