Roles and permissions
Every workspace member has a role that defines what they can see and change. On top of the roles, the CRM attendant has sub-roles that widen or narrow their reach inside the CRM.
Prerequisites: only the Owner and the Admin manage member roles (invite, change role, deactivate/remove). All the roles below depend on the member having an active seat in the workspace.
Workspace roles
Descriptions as shown on the Manage role screen.
Roles that can be invited
The Owner role cannot be assigned: it exists only for whoever created the account. The rest can be set when inviting someone or when managing a member's role.
Subscription and billing
The plan applies to the whole workspace: every member works under the owner's plan. Touching that plan — and seeing what it costs — is restricted to Owner, Administrator and Finance.
Anyone outside those screens still lives with the plan in practice — quota warnings and available features are the workspace's — but the paid-feature notice does not offer a way to buy: whoever handles the subscription is the one who resolves it.
Attendant sub-roles (CRM)
The Attendant role has a sub-role inside the CRM. The Coordinator is an attendant with a workspace-wide view; the others see only their own records. A new attendant starts out as Attendant.
Scope restrictions in the CRM
Some roles can read the whole CRM but cannot perform actions whose reach goes beyond what they can see. The actions below are denied to the Guest and to the Attendant (except the Coordinator sub-role).
A denied action returns a permission error (403). Reading stays open so the attendant can filter and understand the lead.
What the Attendant sees in the side menu
The side menu only shows what the role can reach. For an Attendant without the Coordinator sub-role it is reduced to the Contacts & Commercial section — the Opportunities group, inside Collections.
Guest and Finance follow the same logic: the item disappears from the menu when the role cannot reach the screen.
Related
If it didn't work
- An action was blocked even with the right role: see when "no permission" appears.
- The attendant cannot see other people's records: that is expected; check the sub-role in assigning attendants.
- You got a 403 error when creating a list/segment or exporting contacts: check the error codes.