Team and Roles
Bring colleagues into your workspace and decide what each of them can reach. Invitations and member management live on the Team page; the permissions themselves are defined under Access Roles, and every sensitive change is recorded in the audit log.
Invite and manage members
- Open Team (
/dashboard/team). - Select Add Member to open the Invite a Team Member panel.
- Enter an Email address and pick a role from the dropdown.
- Select Send Invite. The invitee receives an email shortly.
The header shows how many seats you're using — a count of seats used against your limit, or "active (unlimited seats)" on a plan with no cap. Pending invitations count against your seat limit. If you hit the cap you'll see "Seat limit reached. Upgrade your plan or revoke a pending invitation." Seat limits come from your plan; see Billing.
For an existing member you can change their role from the role dropdown on their row, or use Suspend (locks them out until reactivated), Reactivate, and Remove (access ends immediately). Each action asks you to confirm first.
Under Pending Invitations you can Resend an invitation or Revoke one that's no longer needed.
Choose the right role
The invite dropdown offers the built-in roles Guest, Viewer (read-only), Member, Manager, Admin, and Owner. Onboarding presents the three you'll use most — Member, Manager, and Admin. Two of the built-ins carry an explanation in the UI:
- Viewer (read-only) — "Can view everything, cannot make changes."
- Collaborator (Projects & Grants) — "Access limited to CRM, Projects, and Grants."
A Professional (scoped) group holds Accountant, Auditor, and Collaborator (Projects & Grants) for outside advisors. Any custom roles you've built appear in a Custom roles group in the same dropdown.
Build a custom role
Access Roles (/dashboard/settings/access-roles) is where the real permission model lives. You
must be a tenant owner or admin to open it — everyone else sees "You need to be a tenant owner or
admin to manage roles."
- Select New role, or select the copy icon on an existing role to start from its permissions.
- Enter a Name (slug) — lowercase letters, numbers, and underscores, such as
regional_manager. This cannot be changed later. - Enter a Display name and an optional Description.
- Fill in the Permissions matrix, then select Save role.
The matrix has a Module column and an Access column, and works three ways:
- CRM, Projects, Grants, Finance, Payroll, Compliance, Documents, Reports, Business, Integrations, and Workflows each take a level of None, Read, or Read & write. Choosing Read & write also grants read.
- Audit log, Billing, Roles, and Users are read-only — tick the Read box or leave it clear.
- Organization settings is a single Enabled toggle.
Roles marked System are read-only; the dialog tells you to clone one to customize it. Custom roles can be edited or deleted from their card, and each card shows how many users hold it and how many permissions it grants.
The builder deliberately does not offer permissions that would let a role escalate itself — such as assigning roles, managing users, managing billing, or deleting the workspace. Those stay with owners and admins.
The Navigation settings page only chooses which modules appear in your sidebar. It is a display preference, not a permission control, and hiding a module there does not restrict access to it. Use Access Roles for that.
Manage CRM roles
CRM Roles & Permissions (/dashboard/settings/roles) is a separate, CRM-scoped model: "Define
roles with granular permissions for CRM entities."
- Select New Role, enter a Name and optional Description, and set the per-entity Permissions.
- Tick Default role (auto-assigned) if new CRM users should receive it automatically.
- Select Save.
To staff a role, open its users panel, search by name or email, and select Add to role. You can set an optional expiry date and a reason — useful for temporary cover — and remove assignments later.
Review the audit log
Audit Logs (/dashboard/settings/audit) tracks security-sensitive actions across your workspace.
The table shows When, User, Action, Resource, Status, and IP, with headline
counts for Total events, Today, Failed, and Top action.
Use Filters to narrow by action (for example user.login), resource type, resource ID, user
email, user ID, IP address, or a free-text search, then select Apply or Clear. Select any row
to see full event details, and use Export CSV to download the filtered results. How long entries
are kept is set by the Audit Log Retention period described in
Account and Security.