
System vs custom roles
- System roles are fixed and read-only: Admin, Developer, Manager, and Agent. You can open one to see exactly what it grants, but you can’t change it.
- Custom roles are roles you create with a tailored permission set, color, and description.
Permission levels
Open a role to see the permission editor. Every resource (Members, Inbox, Contacts, Tables, and so on) is set to one of three levels:| Level | Meaning |
|---|---|
| None | No access to the resource. |
| View | Read-only: can see but not change. |
| Manage | Full access: create, edit, and delete. |

Not every resource offers all three levels. Some are view-only (Analytics, Audit logs) and some are manage-only (Connections, Workflows, Segments). The editor only shows the levels that apply to each resource.
Sub-resources and cascading
Some resources nest a finer-grained permission underneath them:- System roles under Members: whether this role can assign the system Manager and Agent roles to others (never Admin or Developer).
- Agents under Assistants: agent assignment and assistant handoff.
- Table records under Tables: the rows inside tables, separate from the table structure.
Reserved permissions
A few permissions are reserved for Admins and can never be granted through a custom role: SSO and Sub-organizations. They appear in the editor with a “Reserved” badge and can’t be selected.Creating a custom role
Name and color
Give the role a name, pick a color (used for its badge across the workspace), and add an optional description.
Set permissions
For each resource, choose None, View, or Manage. To start from an existing role, use Copy from a role and adjust from there.

You can only grant permissions you hold yourself (the subset rule), so you can never create a role more powerful than your own access.
Assigning roles
Assign custom roles from the members list with Edit roles next to a member, or stage them on an invite.Inviting with custom roles
When you invite a member, pick a system role or one or more custom roles. If you choose custom roles, the invitee joins at the Agent base plus those roles when they accept.
If a staged custom role is deleted before the invite is accepted, the invite is removed.
The permissions matrix
Settings → Members & Roles → Permissions Matrix shows every role (system and custom) as a column and every resource as a row, so you can compare access at a glance.
Plan and visibility notes
- Creating custom roles requires the Business or Enterprise plan. Existing custom roles stay viewable and removable on lower plans, but you can’t create new ones.
- In a white-labeled workspace, members with the Manager, Agent, or a custom role can’t see Admin or Developer members. This keeps a clean, branded experience for client-side teams.