Command Palette

Search for a command to run...

Workspace Roles

Understand role permissions and access management inside a workspace.

Overview

Workspace roles determine what users can see and do within a specific workspace. These roles span from full administrative control to focused, bot-level operational access.

  • Workspace Admins have total control over workspace settings, members, and all underlying bots.
  • Workspace Moderators assist with day-to-day management like creating bots and managing standard members.
  • Workspace Members have restricted access, typically limited to the specific bots they have been assigned to.

Workspace Permission Matrix

Workspace Action / PermissionAdminModeratorMember
View Workspace DetailsAllowedAllowedAllowed
Edit Workspace Name / MetadataAllowedAllowedNot Allowed
Delete WorkspaceAdmin OnlyNot AllowedNot Allowed
Archive WorkspaceAllowedNot AllowedNot Allowed
Restore WorkspaceAllowedNot AllowedNot Allowed
View Workspace Members ListAllowedAllowedOptional Read-only
Add Members to WorkspaceAllowedAllowedNot Allowed
Remove Members from WorkspaceAllowedCannot Remove AdminNot Allowed
Assign Workspace RolesAllowedMember Role Rec.Not Allowed
Promote Member → ModeratorAllowedOptionalNot Allowed
Promote Moderator → AdminAdmin OnlyNot AllowedNot Allowed
Demote Workspace AdminAdmin OnlyNot AllowedNot Allowed
Create Bots Inside WorkspaceAllowedAllowedNot Allowed
Edit Any Bot in WorkspaceAllowedBased on BLACBased on BLAC
Delete Any Bot in WorkspaceAllowedNot AllowedNot Allowed
Assign Bot-Level RolesAllowedAllowedNot Allowed
View All Bots in WorkspaceAllowedAllowedAssigned Bots Only
Access Unified InboxAll BotsAssigned Bots OnlyAssigned Bots Only
View Workspace AnalyticsFull AccessRead-onlyLimited
Export Workspace ReportsAllowedOptionalNot Allowed
Configure IntegrationsAllowedNot AllowedNot Allowed
Manage Workspace ChannelsAllowedOptionalNot Allowed
View Workspace Audit LogsAllowedRead-onlyNot Allowed
Export Workspace Audit LogsAllowedNot AllowedNot Allowed

Role Descriptions

Workspace Admin

The highest level of access within a workspace. Admins have complete control over all settings, members, bots, and billing/integration configurations. They can perform destructive actions such as deleting the workspace or removing other admins.

Workspace Moderator

Moderators help manage the day-to-day operations of the workspace. They can invite standard members, assign them to bots, and view workspace-level analytics. They cannot manage integrations, delete the workspace, or modify admin permissions.

Workspace Member

The default role for new users added to a workspace. Members only see the bots explicitly assigned to them via Bot-Level Access Control (BLAC). They cannot modify workspace settings, invite users, or view global analytics.

Workspace Governance Rules

  • Every workspace must have at least one Workspace Admin. You cannot demote or remove the final Admin unless transferring ownership.
  • Moderators cannot escalate privileges. A Moderator cannot promote themselves or a Member to Admin status.
  • Role inheritance. Users who are Organization Admins inherently have Workspace Admin privileges across all workspaces, even if not explicitly added.

Unified Inbox Access Model

The Unified Inbox consolidates conversations from all bots in the workspace. However, access to these conversations is strictly filtered by roles:

  • Workspace Admins see all conversations from all bots in the workspace inbox.
  • Moderators and Members only see conversations routed to the bots they are explicitly assigned to manage.

Bot-Level Access Control (BLAC) Explanation

A Workspace Member's ability to edit a bot depends entirely on BLAC.

If a Member is assigned as a Bot Support Agent, they can only view inbox messages and respond to users.

If a Member is assigned as a Bot Developer, they can modify the bot's AI prompts, training data, and behavioral settings within that workspace.

Note: Workspace Admins bypass BLAC and have implicit Bot Developer access to all bots.

Best Practices

  • Limit Workspace Admins. Only grant Admin access to trusted IT personnel or primary business owners.
  • Use Moderators for Team Leads. If a manager needs to oversee a department's bots and invite their team, make them a Workspace Moderator rather than an Admin.
  • Default to Member. Always start users with the Workspace Member role and use BLAC to grant them access to only the specific bots they work on.