Member
Default role for new accounts
Read the workspace and act on their own work. Cannot see other people's drafts, billing, or settings.
- Users
- 5,218
- Permissions
- 14
Every account holds exactly one base role. Groups and admin grants layer on top of it.
Default role for new accounts
Read the workspace and act on their own work. Cannot see other people's drafts, billing, or settings.
Content and collaboration
Everything a Member can do, plus creating and editing shared content across their team.
Team leadership
Editor rights plus team oversight: approve requests, view reports, and manage their team's membership.
Workspace administration
Manage users, roles, groups, and integrations. Scoped variants exist for teams, billing, and security.
Unrestricted access
Everything, including billing, workspace deletion, and granting Owner to others. Keep this list short.
Start from a base role and adjust individual permissions.
| Role | Based on | Users | Permissions | Created by | Last changed | Actions |
|---|---|---|---|---|---|---|
Support Lead Escalation queue + refunds |
Manager | 18 | 34 | Sofia Oliveira | Aug 12, 2026 | |
Contractor Time-boxed, no export |
Member | 64 | 9 | Lucia Ferrero | Jul 30, 2026 | |
Analyst (read-only) Reports and exports, no writes |
Member | 41 | 12 | Noah Whitfield | Jul 18, 2026 | |
Service account API only, no interactive sign-in |
Member | 27 | 6 | Tomas Berg | Jun 09, 2026 |
Base role across all 8,942 accounts
Signals worth acting on
48 owners is unusually high
Most workspaces this size run 3–5.
27 service accounts sign in interactively
They should be API-only.
No role grants delete on billing
Matches the retention policy.
Custom roles all derive from a base
No orphaned permission sets.