How permissions work
Every role is built from a list of features - Inbox, Contacts, Leads, Workflows, and so on - and for each feature you set two things, in this order:
- Access - the checkbox next to the feature. It answers one question: can this person open this section at all? Off means the feature is out of reach for them.
- Actions - the things you can do inside a feature, like Create Contact, Edit Contact, Delete Contact. These only matter once access is on.
That two-step is the whole model. The same feature can sit at four different levels depending on how you set the dials:
They can’t open this section at all.
They can open it and look, but change nothing.
They can do the actions you tick - here, create and edit but not delete.
Access plus every action in the feature.
The built-in roles
Exabloom ships with a fixed set of built-in roles you can’t edit or delete. There are two families, because there are two layers of access - your account-wide Brand and the Workspaces inside it. Both live on the Roles page (drawn in full in the next section); here is how each family’s table reads.
Workspace roles
What someone can do inside a single workspace. New invites default to Agent.
- Admin - every feature, every action, including the workspace’s own Settings tabs. The full set: 27 of 27 features, 22 of 22 actions.
- Agent - the everyday rep. Full Inbox (can send), read-only on contacts, leads, calendar, workflows, analytics and forms - so they can run a workflow but not edit it. Settings is switched on only so they can log out; none of its tabs are.
- Viewer - look but don’t touch. Read-only across the main features, no actions anywhere, no Settings tabs - handy for an auditor or stakeholder.
Brand roles
Account-wide powers - managing users, roles, workspaces and Brand-level features. One per person.
- Owner - full account-wide access. Every Brand keeps at least one Owner, and only Owners can change someone’s Brand role.
- Admin - runs the account day to day: users, roles, workspaces and the Brand-level features. In practice the same reach as Owner (see the note below).
- Member - no Brand-level powers at all (0 of 7 features). A Member only has the Workspace access you grant them - the default for most reps.
Where roles live
Roles are managed in one place: the Roles page in your Brand Admin Dashboard, not inside a workspace. You need Brand-level User Management access to see it (Owners and Admins have it). Three clicks from anywhere in the app.
Open the Admin Dashboard
Don’t see Admin Dashboard? You’re not an Owner or Admin of that Brand and your Brand role doesn’t include any admin feature. Ask whoever owns the account.
Open People, then Roles
The sidebar changes to the Admin Dashboard’s own, with a violet Admin view badge under your brand. Roles is under the People group, right below Users.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Find your way around the page
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
- Workspace roles / Brand roles toggle - switches which layer you’re looking at. A role belongs to one layer or the other; the two lists never mix.
- The Access column - a quick read of how much each role grants, as features · actions. A workspace has 27 features (every Settings tab counts as one) and 22 actions across them, so a full Admin reads 27/27 features · 22/22 actions.
- Clone - on every row, including built-ins. The fast way to make a custom role: duplicate one that’s close, then adjust.
- Edit and Delete - greyed out on built-in rows (they read “Built-in roles cannot be edited” and “Built-in roles cannot be deleted” on hover), active on your own custom roles.
Open a role and read the editor
Click anywhere on a role’s row and its drawer slides in from the right. On a custom role you can rename it, change its recommended visibility and edit every permission. On a built-in role the same drawer opens locked, with a violet note that reads “This is a built-in role. Permissions are locked.” - your cue to Clone it.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
When this role is assigned to a user, their contact visibility auto-fills to this value. Admins can still override it per user.
A built-in role opens the same drawer, read-only. It has no Save button, only Clone and Close:
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Here is the editor at full size, so you can read it. Each row is a feature; the checkbox is access; the arrow opens its actions. The summary on the right tells you the state at a glance.
Conversations across channels
CRM contact records and folders
Lead records and preset filters
Automations and triggers
Open settings page (required for logout)
Activity history and audit trail
Lead pipeline stages
Reading it top to bottom:
- Inbox is on with All actions - it has a single action (send messages), so it’s either full or nothing.
- Contacts is expanded. Allow all actions is off and we’ve hand-picked Create and Edit but not Delete - so the summary reads 2/3 actions.
- Leads is on with 0/3 actions - accessible but read-only. They can browse leads, not change them.
- Workflows is off - No access. The whole section is out of reach for this role.
- Settings carries a padlock - it’s always on and can’t be switched off (it’s required to reach things like logout). Its individual tabs - Audit Log, Pipelines, and the rest - nest underneath and are each granted on their own.
Create or clone a role
When no built-in fits, build your own. Two ways in, both from the Roles page: start from a template in a short dialog, or clone the closest role in one click.
Create a role from the dialog
Best when you want to start clean, or from a template you pick. The dialog only sets the role up; you fine-tune the permissions in the drawer afterwards.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Applies to a user within a single workspace.
Templates pre-fill the permission matrix. You can edit everything after creating the role.
Auto-fills the visibility field when this role is assigned. Admins can still override per user.
- Scope - Workspace role or Brand role. It starts on whichever tab you had open and is fixed once created - a role can’t move between layers later, so pick the right one. Changing it in the dialog clears the template.
- Start from template - Blank - no permissions, or any existing role of that scope (each shows Built-in or Custom) to copy its matrix as a starting point. Either way you edit it after.
- Role name (required) and Description - what teammates will see in the role dropdown. A clear description saves you re-reading the matrix later.
- Recommended contact visibility (Workspace roles only) - a default that auto-fills when the role is assigned, starting at All contacts. It’s only a suggestion; see What a role doesn’t control.
Press Create role and it joins the list. Click its row to open the drawer and tune the permissions exactly as you want - then it’s ready to assign from the user drawer like any built-in.
Or clone the closest role
Best when an existing role is almost right. There’s no dialog: the copy appears straight away, named after the original with (copy) on the end, a Custom role you can rename in its drawer.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Rename, clone or delete a role
Everything you can do to an existing custom role is in its drawer, along the bottom bar: Delete on the left, Clone and Save changes on the right. Delete and Clone are also on the role’s row. Scope is the one thing you can’t change.
A role that someone is still using can’t be deleted. The dialog checks first, lists the people on it, and keeps the red button disabled until you’ve moved every one of them to another role.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
Built-in roles cannot be edited or deleted, but you can Clone any role to start a new custom one with its permissions already filled in.
You’re about to delete Customer Success. This action cannot be undone.
2To move people, change their role from the user drawer (see Invite your team & manage roles), then come back and delete. Deleting can’t be undone.
What a role doesn’t control
A role decides what features and actions a person gets. It deliberately stops there. Two important things are set per person, not by the role - both when you invite or edit someone:
- Contact visibility - whose contacts they see (All contacts, Assigned + unassigned, or Assigned only). A role can recommend a default, but the real setting lives on the person and an admin can override it.
- Pipeline access - which pipelines in a workspace they can work. Also per person, not baked into the role.
Roles to copy
Four custom roles worth building. Each starts by cloning a built-in (or starting blank), then changing just a dial or two.
A rep you trust to create and edit, but who should never delete a contact or lead. The classic reason to leave the built-ins behind. Remember the Bulk Actions side door.
A frontline messenger who lives in the Inbox and nothing else - no contacts, leads, or workflows cluttering their view.
A manager or stakeholder who should read analytics and leads but touch nothing. Like Viewer, but trimmed to just what they review.
A Brand-level operator who manages knowledge, exports and links across the account, but shouldn’t add or remove people.
Good to know & pitfalls
- Access on, zero actions is read-only - not locked. To take a feature away, untick the feature itself. Leaving it on with no actions still lets people open and browse it.
- Bulk Actions can bypass a feature’s own limits. Bulk delete, update and message are gated separately from the per-record actions - so withhold a destructive action in both the feature (Contacts, Leads) and Bulk Actions, not just one.
- Built-ins can’t be edited - clone them. Admin, Agent, Viewer, Owner and Member are fixed. To tweak one, Clone it into a custom role and edit the copy.
- Scope is permanent. A role is a Workspace role or a Brand role for life. If you pick wrong, recreate it under the right scope - there’s no move.
- Owner’s special powers aren’t in the matrix. Changing Brand roles and the last-Owner safeguard are built in, so a custom role cloned from Owner won’t inherit them.
- A role doesn’t set visibility or pipelines. Those are per-person. The role’s “recommended visibility” only pre-fills the field; admins still set it on each teammate.
- Settings can’t be switched off. The Settings umbrella is always on so people can reach essentials like logout - but you control each Settings tab underneath it individually.
- A role in use can’t be deleted. The delete dialog lists who’s on it and stays disabled until you’ve reassigned every one of them.
- Your plan still has the last word. A role can only grant features your subscription includes. If a feature is missing for everyone, the role isn’t the reason - ask us about your plan.
Need a hand?
Our Singapore-based team is one message away - happy to help you get set up.