Brand, Workspaces & seats
Access in Exabloom has two layers, and almost everything else makes sense once you see them. Your Brand is your top-level account. Inside it live one or more Workspaces, typically an HQ plus a Workspace per outlet, client, or business unit, each often with its own WhatsApp number.
That nesting gives every teammate two kinds of role:
- Brand role: account-wide powers such as managing Workspaces, people, roles, and Brand-level features. One per person.
- Workspace role: what they can do inside a single Workspace: inbox, contacts, leads, workflows. Set separately for each Workspace you add them to.
Who can invite & assign roles
Managing people is a Brand-admin job. Out of the box:
- Owners and Admins can invite teammates, edit their access, and remove them.
- Only Owners can set or change someone’s Brand role. For everyone else that dropdown is locked with a padlock and the note “Only Owners can change agency roles.”
- Members have no people-management powers at all.
Find the Users page
Everything in this guide happens on one screen, and it’s two clicks from anywhere in the app. Nothing here lives in the Settings menu of a Workspace: the Users page belongs to the Brand, so you reach it through the Admin Dashboard.
Open the switcher, then Admin Dashboard
The switcher lists your Brands on the left and, on the right, the Workspaces inside the Brand you’re viewing. It’s how you move between Workspaces day to day, and it’s the only door into the Admin Dashboard.
Click Users under People
What the Admin Dashboard opens on depends on your Brand, so the page beside the sidebar may look different to the sketch above. The sidebar is the same. A few other entries in it (Plan & Usage, for one) only appear for some accounts.
Invite a new teammate
This is the path for someone who isn’t in your Brand yet. If they already appear in the Users table, skip to Give an existing teammate access below: inviting them a second time isn’t how you widen their access.
Click Add user
The Invite user drawer slides in from the right. Only the email is required; everything else has a sensible default you can leave alone.
Fill in the drawer and send
Add a teammate and configure their access.
No agency-level powers. Only sees the organisations they are explicitly assigned to.
Full access to the org - settings, users, and every feature.
Using the recommended default for Admin. Sees every contact in the org.
The fields, in order:
- 1Full name: optional, and you can leave it blank. Until they set up their login their name shows as the first part of their email address; you can correct it later from Edit user.
- 2Email: required. This is where the invite goes.
- 3Brand role: defaults to Member. Covered next.
- 4Workspace access: tick each Workspace to grant, then tune its role and contact visibility. Untouched, every Workspace is No access. With more than five Workspaces the list gains a Search workspaces… box and an Enabled only filter.
Most invites need almost none of that. Here’s the fast path versus the parts you can save for when you actually need them:
- 1Type their email
- 2Leave Brand role on Member
- 3Tick their Workspace, leave the role on Admin
Hit Send invitation and you’re done: a teammate who can work that Workspace fully, with no account-wide powers.
Reach for these only when you actually want to hold something back: narrowing the Workspace role to Agent or Viewer, tightening contact visibility, limiting them to specific pipelines, or handing out a stronger Brand role (Admin or Owner).
Check their row
If the email already belongs to someone in this Brand you’ll be told to edit them instead. If it belongs to a person who already has an Exabloom login elsewhere, they’re simply added to your Brand and invited to the Workspaces you ticked.
Give an existing teammate access
Opening a second outlet, or someone’s covering another branch this month? You don’t invite them again. They’re already in your Brand and already using their seat: you just widen what that one account reaches.
Click their row
The same drawer reopens, this time headed Edit user, holding everything they have today.
Tick the Workspace, then Save changes
Change access, roles, and contact visibility.
No agency-level powers. Only sees the organisations they are explicitly assigned to.
Inbox, contacts, leads, workflows (run, not edit). No settings, no user management.
Using the recommended default for Agent. Sees contacts assigned to them, plus any unassigned contacts.
Full access to the org - settings, users, and every feature.
Using the recommended default for Admin. Sees every contact in the org.
Every Workspace in your Brand is listed. The ones they have are ticked and open, the rest read No access. A newly ticked Workspace opens with three dials:
- Role lands on Admin: full run of that Workspace, nothing outside it. Leave it unless you want to hold something back.
- Contact visibility lands on All contacts.
- Pipeline access lands on All pipelines.
The reverse works the same way: to take a Workspace away, untick it in this drawer and save. They keep every other Workspace, their seat, and their login. See Edit access & remove people below for the fuller picture.
The Brand role
The Brand role answers one question: how much of the account can this person run? There are three built-in roles, from most to least powerful:
Runs the whole Brand. Everything an Admin can do plus changing other people’s Brand roles. A Brand can have several Owners, but must always keep at least one.
Manages the Brand day to day: invite and edit teammates, manage Workspaces, and run Brand-wide features. Can’t change anyone’s Brand role - that’s Owner-only.
No Brand-admin powers. A Member only sees the Workspaces you explicitly grant them. This is the default for new invites and the right choice for most reps.
Workspace access
For each Workspace you tick, you set three independent things. They don’t follow each other, and this is the part people most often get wrong, so it’s worth a careful read. First find them on the screen, then read them at full size.
Change access, roles, and contact visibility.
No agency-level powers. Only sees the organisations they are explicitly assigned to.
Inbox, contacts, leads, workflows (run, not edit). No settings, no user management.
Using the recommended default for Agent. Sees contacts assigned to them, plus any unassigned contacts.
Inbox, contacts, leads, workflows (run, not edit). No settings, no user management.
Using the recommended default for Agent. Sees contacts assigned to them, plus any unassigned contacts.
1 · Workspace role
What they can do inside this Workspace. Three built-ins:
Full access to that one Workspace: its settings, users and every feature. Nothing outside it. The simple choice when you just want a teammate up and running - and the one the drawer pre-selects.
The everyday rep: the Inbox in full, plus contacts, leads, calendar and workflows (they can run workflows, not edit them). No settings and no user management.
Read-only access to every feature. Handy for an auditor or a stakeholder who only needs to see what’s going on.
2 · Contact visibility
Whose contacts they see in this Workspace, separate from what they can do. Three choices:
- All contacts: sees every contact in the Workspace.
- Assigned + unassigned: their own contacts, plus anything not yet assigned to anyone.
- Assigned only: only the contacts assigned to them.
Changing the role pre-fills a recommended default (Admin and Viewer suggest All contacts, Agent suggests Assigned + unassigned, and the grey line under the box says “Using the recommended default for Agent”), but you’re free to override it.
3 · Pipeline access
Which lead pipelines in this Workspace they can work. There are two options, and the simple one is the right one most of the time:
- All pipelines: the simple choice, and what the app already selects the moment you tick a Workspace. They can work every pipeline in it, including any you build later. Leave it alone unless you have a reason not to.
- Specific pipelines: tick only the pipelines they should reach. Use this when you genuinely need to control which leads they can get to: a rep who should only touch New Enquiries and never Re-enrolment, say, or a partner working a single campaign.
Like contact visibility, this is independent of the role: picking a smaller role won’t narrow their pipelines for you.
Invites, reminders & expiry
Sending an invitation emails the teammate a link to set up their login. Until they accept, their row shows Pending invite with a countdown to when the link lapses. Once they verify, they flip to Active and their access is live immediately.
The three pills, at full size:
Edit access & remove people
The Edit user drawer you met above isn’t only for adding Workspaces: it’s where every later change happens. Three rules govern it:
- Email is locked. You can change the name, roles, Workspaces, visibility and pipelines, but not the email an invite was tied to. If someone’s address changes, remove them and invite the new one.
- Brand role is Owner-only. If you’re not an Owner, that dropdown is greyed out behind a padlock. Everything below it (Workspaces, roles, visibility, pipelines) you can still edit.
- To remove someone from one Workspace, just untick it here and save. There’s no separate button, and they keep their access to every other Workspace.
Removing someone from the whole Brand is a bigger, deliberate step. It takes two screens: the bin icon on their row, then a confirmation that spells out the consequences and asks you to type their email to be sure.
Click the bin icon on their row
Type their email and confirm
- •Loses access to 1 workspace (Jurong).
- •Contacts and leads assigned to them will be unassigned.
- •Their pending conversations remain in the inbox and can be picked up by teammates.
- •Workflows they created stay in place; audit logs are preserved.
raj@brightminds.sg below.Setups to copy
Five configurations that cover most teams. Each is just the dials above, set together: adapt, don’t copy blindly.
The default answer. Someone who works one branch and should be able to run it, with no account-wide powers.
A salesperson who only works their own leads at a single branch. Set the pipeline restriction after the invite, from Edit user.
Someone who oversees several branches and needs the full picture in each.
An accountant or stakeholder who should see activity but never touch it.
A co-founder or ops lead, so you’re never the only Owner if you step away.
Good to know & pitfalls
- Visibility and pipelines don’t follow the role. Set them on purpose: a “small” role won’t automatically narrow what someone sees or which pipelines they touch.
- A new invite starts on All pipelines. Narrow it afterwards from Edit user.
- Specific pipelines don’t pick up new ones. A pipeline built after you saved their access stays invisible to them until you tick it. All pipelines, the simple setting, keeps up on its own.
- Never re-invite someone who’s already on the team. To give them another Workspace, click their row, tick it, and Save changes. No email goes out and access is live immediately.
- Invites expire in 30 days. The link stops working after that. Use Resend invite to send a fresh one and restart the clock.
- Only Owners change Brand roles, and you can’t remove the last Owner or yourself. Promote a second Owner before you ever need one.
- Removing from the Brand unassigns their work. Their contacts and leads go unassigned and pending chats return to the inbox; workflows they built and the audit log stay put. Removing from a single Workspace just unticks it.
- One seat covers every Workspace. Adding a teammate to more Workspaces never costs another seat.
- A couple of old labels linger. The screen now says Brand and Workspace nearly everywhere, but the Users page still describes itself as “your agency and its organisations” and the Owner lock mentions “agency roles”. Same two layers, older words: agency means your Brand, organisation means a Workspace.
Need a hand?
Our Singapore-based team is one message away - happy to help you get set up.