Roles: what an owner, admin and member can do
The three roles in an organisation, the two extra permissions, and what each can and cannot change.
Roles decide who manages people. They never give anyone a way to read another person's private items.
The three roles
| Role | Can do |
|---|---|
| Owner | Everything an admin can do, invite an admin, grant or remove the admin role, grant the two extra permissions, and holds both permissions automatically. |
| Admin | Invite members, see everyone's email address, suspend or deactivate members, revoke invites, reassign campaigns, read the audit log. |
| Member | Use the product. Sees the member list with names but not other people's email addresses. |
What the rules protect
- Only the owner can invite an admin.
- An admin can change members only, and can never make someone an admin.
- Nobody can change the owner's role or status. The last owner cannot change their own.
- Nothing is deleted: people are suspended or deactivated, invites are revoked.
The two extra permissions
Sensitive powers are separate permissions that only the owner grants.
| Permission | For |
|---|---|
| crm.reveal_sealed | Revealing sealed items in the CRM. |
| crm.privacy_archive | Archiving for privacy reasons in the CRM. |
Statuses
A person is active, suspended or deactivated. A suspended person cannot use the organisation.
Reassigning
An admin can move campaigns from one person to another active member. Only campaigns can be reassigned today.