AM

Roles

Every account holds exactly one base role. Groups and admin grants layer on top of it.

Base roles

Member

Default role for new accounts

System

Read the workspace and act on their own work. Cannot see other people's drafts, billing, or settings.

Users
5,218
Permissions
14

Editor

Content and collaboration

System

Everything a Member can do, plus creating and editing shared content across their team.

Users
2,140
Permissions
23

Manager

Team leadership

System

Editor rights plus team oversight: approve requests, view reports, and manage their team's membership.

Users
1,024
Permissions
31

Admin

Workspace administration

System

Manage users, roles, groups, and integrations. Scoped variants exist for teams, billing, and security.

Users
512
Permissions
42

Owner

Unrestricted access

System

Everything, including billing, workspace deletion, and granting Owner to others. Keep this list short.

Users
48
Permissions
All

Create a custom role

Start from a base role and adjust individual permissions.

Custom roles

Role Based on Users Permissions Created by Last changed Actions

Support Lead

Escalation queue + refunds

Manager 18 34 Sofia Oliveira Aug 12, 2026

Contractor

Time-boxed, no export

Member 64 9 Lucia Ferrero Jul 30, 2026

Analyst (read-only)

Reports and exports, no writes

Member 41 12 Noah Whitfield Jul 18, 2026

Service account

API only, no interactive sign-in

Member 27 6 Tomas Berg Jun 09, 2026

Role distribution

Base role across all 8,942 accounts

Role hygiene

Signals worth acting on

  • 48 owners is unusually high

    Most workspaces this size run 3–5.

  • 27 service accounts sign in interactively

    They should be API-only.

  • No role grants delete on billing

    Matches the retention policy.

  • Custom roles all derive from a base

    No orphaned permission sets.