Permissions

A role sets someone's starting capabilities. Permissions let you adjust those for one person, without changing their role and without affecting anyone else.

Most teams never need this. Reach for it when someone does not fit a role cleanly: an outside contractor who should use what you give them and build nothing of their own, or a trusted member you want to hand one admin job to.

Change someone's permissions

  1. Open Settings, then Members.
  2. Find the person and choose Permissions on their row.
  3. Tick or untick capabilities. A changed row is highlighted so you can see what you have altered.
  4. Choose Save permissions. It takes effect on their next action, with no need for them to sign out.

To put someone back on their role's defaults, open the panel and choose Reset to role, then save.

The capabilities

Grouped the way the panel shows them. The ticks are the defaults each role starts with.

Profiles

CapabilityOwnerAdminMember
See every profile in the workspaceYesYesNo
Shape a profile's access listYesYesNo
Edit or delete any profileYesYesNo
Create new profilesYesYesYes
Edit or delete the profiles you createdYesYesYes

Without See every profile, a person sees the profiles they created, the ones they were assigned to, and any profile that uses a connection they authorised. That last one is visibility only: they can narrow or remove their own connection on it and nothing else. See Roles.

Building a profile is also bounded by what you connected. A member can only add connections they authorised themselves; an owner or admin can add theirs to a member's profile, and it then stays fixed from that member's side.

Connections

CapabilityOwnerAdminMember
Manage any connectionYesYesNo
Connect a vendor with your own loginYesYesYes
Rename, retool, or disconnect the connections you authorisedYesYesYes

Connecting a platform uses one of your plan's connection slots, and premium connectors need a plan that includes them. If you would rather members did not spend those, switch off Connect a vendor with your own login.

Everyone can see every connection in the workspace, which is what makes "already connected" legible. Managing one is the part that is restricted.

Activity

CapabilityOwnerAdminMember
See every call in the workspaceYesYesNo

Without it, Activity shows the calls that person made plus calls made through a connection they authorised, and the CSV export matches. Their monthly figures count only those calls, and the plan's allowance is not shown, because the allowance is the account's and belongs with billing.

Members and invites

CapabilityOwnerAdminMember
View members and pending invitesYesYesNo
Invite a new memberYesYesNo
Remove a memberYesYesNo
Change a member's roleYesYesNo
Revoke a pending inviteYesYesNo
Create or promote ownersYesNoNo

Viewing, sending, resending, and revoking connect links are all admin by default. Connect links also need a plan that includes them, see Connect links.

Account, billing, and notifications

Account settings and billing are owner only. So is the account's email catalog — the list of which emails FloConnector sends on the account's behalf.

Your own notification preferences are not: everyone reaches Settings → Notifications and controls their own bell and email, with the connector notifications set separately for each workspace they belong to. One notification cannot be switched off anywhere — being told that someone added a connector you authorised to a profile. It is how you keep track of your own credentials, so it stays on.

What you cannot adjust

Four capabilities always follow the role and are locked in the panel:

  • View billing
  • Change plan and manage the subscription
  • Update account settings
  • Create or promote owners

These are what make an owner an owner. Moving them per person would let an admin hollow out an owner, or quietly hand out the ability to make more owners. To change who has them, change the person's role.

You also cannot grant a capability you do not hold yourself. An admin can adjust a member, but cannot give that member something the admin does not have.

Changing the role clears your adjustments

Permissions are stored as differences from the role's defaults. Change someone's role and they take that role's defaults, so any adjustments you made no longer apply. Set the role first, then adjust.

A worked example: use only what I give you

This is the common one. You want an outside person to use two endpoints you assign and do nothing else in the workspace.

  1. Invite them as a member, scoped to the one workspace they should work in. See Invite a teammate.
  2. Open Permissions on their row and switch off Create new profiles, Edit or delete the profiles you created, and Connect a vendor with your own login.
  3. Assign them to the profiles they need, see Assign members.

They can now sign in, see exactly the profiles you assigned, and connect those endpoints to their AI client. They cannot build a profile, change one, connect a platform, see your other profiles, or see anything about your other workspaces.

Switching off Connect a vendor with your own login is what closes the last gap. Someone who can connect a platform keeps control of it wherever you use it, and any profile carrying it shows up for them. A contractor who connects nothing has nothing to keep control of, so they only ever see what you assigned.

Going the other way

The panel works upward too. To let one member send connect links without making them an admin, switch on the connect link capabilities for that person and leave their role alone. They gain the Links page and nothing else.

Permissions and profile access are different things

Permissions decide what someone can administer. Profile access decides which endpoints they can use, and it is granted per person on each profile.

Someone can hold every profile permission and still be on no profiles. Someone can be on five profiles and hold no permissions beyond using them. Set both.