How do I control what each person can access?
Access control protects you from two risks: someone seeing what they should not (billing data, the contact base) and someone changing what they should not (publishing a page, deleting a funnel).
Before you start
- Role: Owner or Admin.
- The full table lives in the roles and permissions reference (Portuguese) — this guide is about how to decide, not about listing.
1. Assign by the work, not by the hierarchy
The role should reflect what the person does, not their seniority. Giving everyone Admin avoids friction at the start and creates risk later — including accidental deletion.
2. Know the restrictions that confuse people most
A few restrictions generate support tickets over and over:
- An Attendant cannot write to lists and segments.
- An Attendant without the Coordinator subrole does not manage pipelines, though they can move opportunities in the pipelines they take part in.
- Restricted roles cannot reach whole areas, such as Sales and My Wallet.
- Wallet actions and bank details are Owner level.
3. Refine the support side
Beyond the workspace role, attendants have an attendant type and per-channel authorisation. That is what decides which conversations each person sees — see attendant assignment.
4. Diagnose "a button disappeared"
When someone says an option has vanished, check in this order:
- Does their role allow that action? — roles and permissions reference (Portuguese)
- Are they in the right workspace and project?
- Is it a plan restriction rather than a role one? — limits and quotas reference (Portuguese)
- For conversations, are they authorised on that channel?
The page "You do not have permission to perform this action" covers the most common cases.
5. Review when someone leaves
An exit without an access review is the most common security hole. When someone leaves, remove them and check what they had access to — especially the contact base and the finance area.
Related
- Roles and permissions reference (Portuguese)
- No permission
- Set up your workspace and team
- Data protection in practice
If it didn't work
- You changed the role and nothing changed: ask the person to sign out and sign back in.
- The action is still blocked with the correct role: it may be a plan limit — see the limits and quotas reference (Portuguese).
- The attendant does not see conversations: review their per-channel authorisation.