Roles: what an owner, admin and member can do

The three roles in an organisation, the two extra permissions, and what each can and cannot change.

ReferenceAdminChecked 2026-10-10

Roles decide who manages people. They never give anyone a way to read another person's private items.

The three roles

Role Can do
Owner Everything an admin can do, invite an admin, grant or remove the admin role, grant the two extra permissions, and holds both permissions automatically.
Admin Invite members, see everyone's email address, suspend or deactivate members, revoke invites, reassign campaigns, read the audit log.
Member Use the product. Sees the member list with names but not other people's email addresses.

What the rules protect

  • Only the owner can invite an admin.
  • An admin can change members only, and can never make someone an admin.
  • Nobody can change the owner's role or status. The last owner cannot change their own.
  • Nothing is deleted: people are suspended or deactivated, invites are revoked.

The two extra permissions

Sensitive powers are separate permissions that only the owner grants.

Permission For
crm.reveal_sealed Revealing sealed items in the CRM.
crm.privacy_archive Archiving for privacy reasons in the CRM.

Statuses

A person is active, suspended or deactivated. A suspended person cannot use the organisation.

Reassigning

An admin can move campaigns from one person to another active member. Only campaigns can be reassigned today.