Help Center
Customising your workspaceAdmin only14 min read

Roles & permissions

A role is a saved set of permissions you hand to people. This guide is the model underneath it: how access and actions fit together, what the built-in roles really grant, and how to build a custom role that allows exactly what you intend - no more, no less.
You probably don’t need a custom role
The three built-in Workspace roles - Admin, Agent and Viewer - cover almost every team. Custom roles are for the in-between case the built-ins miss (say, “can edit but never delete”). Read the first two sections, and if a built-in fits, you’re done. This guide is the companion to Invite your team & manage roles, which covers assigning roles to people.

How permissions work

Every role is built from a list of features - Inbox, Contacts, Leads, Workflows, and so on - and for each feature you set two things, in this order:

  • Access - the checkbox next to the feature. It answers one question: can this person open this section at all? Off means the feature is out of reach for them.
  • Actions - the things you can do inside a feature, like Create Contact, Edit Contact, Delete Contact. These only matter once access is on.

That two-step is the whole model. The same feature can sit at four different levels depending on how you set the dials:

No accessNo access
Contactsaccess
Create Contact
Edit Contact
Delete Contact

They can’t open this section at all.

Read-only0/3 actions
Contactsaccess
Create Contact
Edit Contact
Delete Contact

They can open it and look, but change nothing.

Some actions2/3 actions
Contactsaccess
Create Contact
Edit Contact
Delete Contact

They can do the actions you tick - here, create and edit but not delete.

Full accessAll actions
Contactsaccess
Create Contact
Edit Contact
Delete Contact

Access plus every action in the feature.

Access is the gate; actions are what they can change once inside. Turning access on with zero actions is how you make a section read-only.
Access on, zero actions = read-only
This trips people up. Ticking a feature on but leaving every action unchecked doesn’t lock the feature - it makes it read-only. The editor shows that as 0/3 actions, not “No access”. To take a feature away entirely, untick the feature itself.
How the ticks move together
Ticking a feature on turns every action on for you and ticks Allow all actions. Untick a single action and Allow all actions unticks itself - the summary drops to 2/3 actions. Untick Allow all actions itself and it clears every action at once, so you build up from nothing by ticking only what you want. Tick every action by hand and it re-ticks itself. Unticking the feature switches all of it off.

The built-in roles

Exabloom ships with a fixed set of built-in roles you can’t edit or delete. There are two families, because there are two layers of access - your account-wide Brand and the Workspaces inside it. Both live on the Roles page (drawn in full in the next section); here is how each family’s table reads.

Workspace roles

What someone can do inside a single workspace. New invites default to Agent.

Workspace rolesBrand roles
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
The Workspace roles tab. Kind says Built-in; Access counts how many of the workspace’s 27 features and 22 actions the role grants.
  • Admin - every feature, every action, including the workspace’s own Settings tabs. The full set: 27 of 27 features, 22 of 22 actions.
  • Agent - the everyday rep. Full Inbox (can send), read-only on contacts, leads, calendar, workflows, analytics and forms - so they can run a workflow but not edit it. Settings is switched on only so they can log out; none of its tabs are.
  • Viewer - look but don’t touch. Read-only across the main features, no actions anywhere, no Settings tabs - handy for an auditor or stakeholder.

Brand roles

Account-wide powers - managing users, roles, workspaces and Brand-level features. One per person.

Workspace rolesBrand roles
RoleDescriptionKindAccessActions
OwnerPrimary account role. Full access to the agency. An agency can have multiple Owners, but at least one must remain at all times. Built-in7/7 features · 18/18 actions
AdminFull access to the agency - manage organisations, users, roles, and agency-level features. Can be added and removed. Built-in6/7 features · 18/18 actions
MemberNo agency-level powers. Only sees the organisations they are explicitly assigned to. Built-in0/7 features · 0/18 actions
The Brand roles tab. Brand features are a shorter list: 7 features and 18 actions.
  • Owner - full account-wide access. Every Brand keeps at least one Owner, and only Owners can change someone’s Brand role.
  • Admin - runs the account day to day: users, roles, workspaces and the Brand-level features. In practice the same reach as Owner (see the note below).
  • Member - no Brand-level powers at all (0 of 7 features). A Member only has the Workspace access you grant them - the default for most reps.
Owner and Admin are nearly identical
At the permission level the built-in Owner and Admin Brand roles grant the same working features. The things only an Owner can do - change another person’s Brand role and never be the last Owner removed - are built-in safeguards, not switches in the permission matrix. So cloning Owner won’t hand those powers to a custom role.

Where roles live

Roles are managed in one place: the Roles page in your Brand Admin Dashboard, not inside a workspace. You need Brand-level User Management access to see it (Owners and Admins have it). Three clicks from anywhere in the app.

1

Open the Admin Dashboard

app.exabloom.com/conversations
1BMBright MindsOrchard
Inbox
Leads
Calendars
Contacts
Bulk Actions
Win-back
Workflows
Analytics
Forms
Settings
Search
Mei Ling Tan
Hi! I’d like to know more…
Daniel Koh
Is there a trial class?
Priya S.
Thank you!
Aaron Lim
What time on Saturday?
Brands
Find brand...
BMBright Mindsowner
WorkspacesBright Minds
Find workspace...
2
Admin DashboardManage brand settings
Orchard
Tampines
Jurong East
① Click your brand at the top of the left sidebar. A panel opens beside it. ② Click Admin Dashboard, pinned above your workspaces.

Don’t see Admin Dashboard? You’re not an Owner or Admin of that Brand and your Brand role doesn’t include any admin feature. Ask whoever owns the account.

2

Open People, then Roles

The sidebar changes to the Admin Dashboard’s own, with a violet Admin view badge under your brand. Roles is under the People group, right below Users.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
1
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

① Roles, under People. The page it opens is the one every step below starts from.
3

Find your way around the page

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
1
Workspace rolesBrand roles
2What’s the difference?
Search roles…
RoleDescriptionKind3AccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions4
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

① Toggle between Workspace roles and Brand roles. ② What’s the difference? opens a small explainer of the two layers. ③ The Access column. ④ Clone, on every row - Edit and Delete are greyed on built-ins.
  • Workspace roles / Brand roles toggle - switches which layer you’re looking at. A role belongs to one layer or the other; the two lists never mix.
  • The Access column - a quick read of how much each role grants, as features · actions. A workspace has 27 features (every Settings tab counts as one) and 22 actions across them, so a full Admin reads 27/27 features · 22/22 actions.
  • Clone - on every row, including built-ins. The fast way to make a custom role: duplicate one that’s close, then adjust.
  • Edit and Delete - greyed out on built-in rows (they read “Built-in roles cannot be edited” and “Built-in roles cannot be deleted” on hover), active on your own custom roles.
Create role is greyed out?
The Create role button needs Brand-level User Management access. Without it the button is disabled and explains why when you hover it.

Open a role and read the editor

Click anywhere on a role’s row and its drawer slides in from the right. On a custom role you can rename it, change its recommended visibility and edit every permission. On a built-in role the same drawer opens locked, with a violet note that reads “This is a built-in role. Permissions are locked.” - your cue to Clone it.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
1Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

Customer SuccessCustomWorkspace
Works the inbox and contacts; can edit but never delete.
Role name
Customer Success
Description
Works the inbox and contacts; can edit but never delete.
Recommended contact visibility

When this role is assigned to a user, their contact visibility auto-fills to this value. Admins can still override it per user.

Assigned + unassigned
Permissions
Inbox
Conversations across channels
All actions
Contacts
CRM contact records and folders
2/3 actions3
Allow all actions
Create Contact
Edit Contact
4Delete Contact
2
Workflows
Automations and triggers
No access
Settings
Open settings page (required for logout)
Enabled
Delete Clone5Save changes
① Click the role’s row. ② A feature’s checkbox is its access: tick or untick it. ③ The arrow at the right of a feature opens its actions. ④ Each action has its own checkbox. ⑤ Save changes, bottom right - nothing counts until you do.

A built-in role opens the same drawer, read-only. It has no Save button, only Clone and Close:

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

Agent Built-inWorkspace
Inbox, contacts, leads, workflows (run, not edit). No settings, no user management.
This is a built-in role. Permissions are locked. Use Clone to create a custom role with this role’s permissions as a starting point.
Recommended contact visibility
Assigned + unassigned
Sees contacts assigned to them, plus any unassigned contacts.
Permissions
Inbox
Conversations across channels
All actions
Contacts
CRM contact records and folders
0/3 actions
Workflows
Automations and triggers
0/3 actions
1 CloneClose
① On a built-in role the drawer is locked: no Save, no Delete, just Clone and Close. The permission list is drawn the same, greyed.

Here is the editor at full size, so you can read it. Each row is a feature; the checkbox is access; the arrow opens its actions. The summary on the right tells you the state at a glance.

Inbox

Conversations across channels

All actions
Contacts

CRM contact records and folders

2/3 actions
Allow all actions
Create Contact
Edit Contact
Delete Contact
Leads

Lead records and preset filters

0/3 actions
Workflows

Automations and triggers

No access
Settings

Open settings page (required for logout)

Enabled
Settings/Audit Log

Activity history and audit trail

Enabled
Settings/Pipelines

Lead pipeline stages

No access
The permission list, at full size. A workspace role mid-edit.

Reading it top to bottom:

  • Inbox is on with All actions - it has a single action (send messages), so it’s either full or nothing.
  • Contacts is expanded. Allow all actions is off and we’ve hand-picked Create and Edit but not Delete - so the summary reads 2/3 actions.
  • Leads is on with 0/3 actions - accessible but read-only. They can browse leads, not change them.
  • Workflows is off - No access. The whole section is out of reach for this role.
  • Settings carries a padlock - it’s always on and can’t be switched off (it’s required to reach things like logout). Its individual tabs - Audit Log, Pipelines, and the rest - nest underneath and are each granted on their own.
Features without actions just say “Enabled”
A handful of features have no actions to pick - the Settings tabs, Analytics and Win-back. For those, access is the whole story, so the summary reads Enabled or No access rather than a count. There is no read-only setting for a Settings tab: Enabled means the tab, in full.
Bulk Actions is a separate gate - mind the overlap
A few actions exist in two features at once, and the two don’t check each other. Deleting contacts is the one to watch: Contacts has Delete Contact, while Bulk Actions has its own Perform Bulk Action Delete Contact. Turn delete off under Contacts but leave it on under Bulk Actions, and that person still can’t delete a contact from its row - yet they can select many and delete them in one bulk run. So when you withhold a destructive action, switch it off in both features, or you’ve left a side door open. The same overlap covers bulk field-updates and bulk messaging.

Create or clone a role

When no built-in fits, build your own. Two ways in, both from the Roles page: start from a template in a short dialog, or clone the closest role in one click.

1

Create a role from the dialog

Best when you want to start clean, or from a template you pick. The dialog only sets the role up; you fine-tune the permissions in the drawer afterwards.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
1 Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

Create role
Scope
2Workspace role

Applies to a user within a single workspace.

Start from template
3Blank - no permissions

Templates pre-fill the permission matrix. You can edit everything after creating the role.

Role name
4Customer Success
Description
5Works the inbox and contacts; can edit but never delete.
Recommended contact visibility
6All contacts

Auto-fills the visibility field when this role is assigned. Admins can still override per user.

Cancel7Create role
① Create role, top right of the Roles page. In the dialog: ② Scope. ③ Start from template. ④ Role name. ⑤ Description. ⑥ Recommended contact visibility. ⑦ Create role.
  • Scope - Workspace role or Brand role. It starts on whichever tab you had open and is fixed once created - a role can’t move between layers later, so pick the right one. Changing it in the dialog clears the template.
  • Start from template - Blank - no permissions, or any existing role of that scope (each shows Built-in or Custom) to copy its matrix as a starting point. Either way you edit it after.
  • Role name (required) and Description - what teammates will see in the role dropdown. A clear description saves you re-reading the matrix later.
  • Recommended contact visibility (Workspace roles only) - a default that auto-fills when the role is assigned, starting at All contacts. It’s only a suggestion; see What a role doesn’t control.

Press Create role and it joins the list. Click its row to open the drawer and tune the permissions exactly as you want - then it’s ready to assign from the user drawer like any built-in.

2

Or clone the closest role

Best when an existing role is almost right. There’s no dialog: the copy appears straight away, named after the original with (copy) on the end, a Custom role you can rename in its drawer.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions1
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Admin (copy)Full access to the org - settings, users, and every feature.Custom27/27 features · 22/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

Role cloned
① Clone on any row, built-in or custom. The frame below is the result a moment later: a new Custom row, and a “Role cloned” message bottom right.

Rename, clone or delete a role

Everything you can do to an existing custom role is in its drawer, along the bottom bar: Delete on the left, Clone and Save changes on the right. Delete and Clone are also on the role’s row. Scope is the one thing you can’t change.

A role that someone is still using can’t be deleted. The dialog checks first, lists the people on it, and keeps the red button disabled until you’ve moved every one of them to another role.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions1

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

app.exabloom.com/agency/roles
BMBright MindsAdmin view
Analytics
Analytics
Billing & Usage
WhatsApp Business
People
Users
Roles
AI & Knowledge
AI Agents
Knowledge Hub
Internal InputBeta
AI Feedback
Tools
Exports
Website Chat Widget
Redirect Links
Logout
Roles
Control what people can see and do across your brand and its workspaces.
Create role
Workspace rolesBrand roles
What’s the difference?
Search roles…
RoleDescriptionKindAccessActions
AdminFull access to the org - settings, users, and every feature. Built-in27/27 features · 22/22 actions
AgentInbox, contacts, leads, workflows (run, not edit). No settings, no user management. Built-in8/27 features · 1/22 actions
ViewerRead-only access to every feature in the org. Built-in9/27 features · 0/22 actions
Customer SuccessWorks the inbox and contacts; can edit but never delete.Custom5/27 features · 3/22 actions

Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.

Delete role

You’re about to delete Customer Success. This action cannot be undone.

2
Reassign 2 users to delete this role.In use
MTMei Tanmei@brightminds.sgOrchard
ANArjun Nairarjun@brightminds.sgOrchard
Cancel3 Delete role
① Delete on the row (or in the drawer). ② The dialog lists every user still on the role. ③ Delete role stays grey until that list is empty.

To move people, change their role from the user drawer (see Invite your team & manage roles), then come back and delete. Deleting can’t be undone.

What a role doesn’t control

A role decides what features and actions a person gets. It deliberately stops there. Two important things are set per person, not by the role - both when you invite or edit someone:

  • Contact visibility - whose contacts they see (All contacts, Assigned + unassigned, or Assigned only). A role can recommend a default, but the real setting lives on the person and an admin can override it.
  • Pipeline access - which pipelines in a workspace they can work. Also per person, not baked into the role.
Two people, same role, different reach
Because visibility and pipelines ride on the person, two teammates on the exact same role can still see different contacts. If a rep should only see their own customers, set Assigned only on them - choosing a “smaller” role won’t do it. Invite your team & manage roles covers those per-person dials in full.

Roles to copy

Four custom roles worth building. Each starts by cloning a built-in (or starting blank), then changing just a dial or two.

1 · Editor, never deleter

A rep you trust to create and edit, but who should never delete a contact or lead. The classic reason to leave the built-ins behind. Remember the Bulk Actions side door.

WorkspaceClone: AdminKeep Create + EditUntick all DeleteBulk Actions: both Delete off
2 · Inbox-only agent

A frontline messenger who lives in the Inbox and nothing else - no contacts, leads, or workflows cluttering their view.

WorkspaceStart blankInbox: onEverything else: off
3 · Reporting viewer

A manager or stakeholder who should read analytics and leads but touch nothing. Like Viewer, but trimmed to just what they review.

WorkspaceClone: ViewerAnalytics + Leads: readUntick the rest
4 · Brand ops, no user control

A Brand-level operator who manages knowledge, exports and links across the account, but shouldn’t add or remove people.

BrandClone: AdminKeep Brand featuresUser Management: off

Good to know & pitfalls

  • Access on, zero actions is read-only - not locked. To take a feature away, untick the feature itself. Leaving it on with no actions still lets people open and browse it.
  • Bulk Actions can bypass a feature’s own limits. Bulk delete, update and message are gated separately from the per-record actions - so withhold a destructive action in both the feature (Contacts, Leads) and Bulk Actions, not just one.
  • Built-ins can’t be edited - clone them. Admin, Agent, Viewer, Owner and Member are fixed. To tweak one, Clone it into a custom role and edit the copy.
  • Scope is permanent. A role is a Workspace role or a Brand role for life. If you pick wrong, recreate it under the right scope - there’s no move.
  • Owner’s special powers aren’t in the matrix. Changing Brand roles and the last-Owner safeguard are built in, so a custom role cloned from Owner won’t inherit them.
  • A role doesn’t set visibility or pipelines. Those are per-person. The role’s “recommended visibility” only pre-fills the field; admins still set it on each teammate.
  • Settings can’t be switched off. The Settings umbrella is always on so people can reach essentials like logout - but you control each Settings tab underneath it individually.
  • A role in use can’t be deleted. The delete dialog lists who’s on it and stays disabled until you’ve reassigned every one of them.
  • Your plan still has the last word. A role can only grant features your subscription includes. If a feature is missing for everyone, the role isn’t the reason - ask us about your plan.

Need a hand?

Our Singapore-based team is one message away - happy to help you get set up.