Roles

Every workspace member holds one role. Roles govern administration; access to a given profile is still granted per person on top of the role.

The four roles

RoleCan do
Primary ownerEverything an owner can, plus owns billing and can transfer the account. One per account.
OwnerManage connections, profiles, and members. Add other owners.
AdminManage connections and profiles, see every profile and every call in the workspace, and edit profile membership. Cannot reach billing or promote owners.
MemberUse the profiles they are assigned to. By default they can also create their own profiles and connect their own accounts, and they keep control of any connection they authorise wherever it is used.
Owners add, they do not remove peers

Owners can promote others to owner, but no one removes a peer owner. Ownership of the account itself moves only through a deliberate transfer by the primary owner.

Adjusting one person's permissions

A role is a starting point, not the whole answer. On any member's row in Settings → Members, choose Permissions to switch individual capabilities on or off for that one person, without changing their role or affecting anyone else.

That is how you produce a login that uses the endpoints you assign it and nothing else, and equally how you hand one member a single admin job without making them an admin. Billing, account settings, and promoting owners always follow the role.

For the full capability list and worked examples, see Permissions.

Account-wide vs workspace-scoped

A role can apply to your whole account or to specific workspaces. A standard account owner and admin are account-wide. When you invite someone into a single workspace (for example an agency you bring into one client), their role is scoped to that workspace.

A scoped owner or admin administers the connections and profiles in the workspaces they hold. Actions that belong to the account as a whole need account-wide standing:

  • Members (viewing the roster, inviting people, changing roles, removing others) is managed at the account level. A workspace-scoped admin cannot see or change the members of other workspaces.
  • Billing belongs to the primary owner. A workspace-scoped owner never reaches the account's plan or payment method.

This is what keeps an agency and its client from getting entangled: an agency scoped into a client's workspace runs that workspace without touching the client's member list or billing, and vice versa.

Roles and profile access

A role decides what you can administer. It does not decide which profiles you can use. An admin can edit any profile's member list but is only on the profiles they have been added to. See Assign members.

Owners and admins see every profile in the workspace. For everyone else, visibility is not about the role at all: it is about your relationship to that profile. There are three, and they stack.

BecauseYou can
You created itRename it, change what it exposes, delete it
You are assigned to itConnect an AI client and use it
It uses a platform you connectedSee it, and narrow or remove your connection on it
flowchart TD

    P(["A profile in this workspace"]) --> R{"Owner or<br/>admin?"}

    R -->|Yes| ALL["<b>Sees everything</b><br/>Full control of the profile"]

    R -->|No| C{"You<br/>created it?"}

    C -->|Yes| MINE["<b>It is yours</b><br/>Edit or delete it"]

    C -->|No| A{"Assigned<br/>to you?"}

    A -->|Yes| USE["<b>You can use it</b><br/>Connect an AI client to the endpoint"]

    A -->|No| K{"Uses your<br/>connector?"}

    K -->|Yes| AGENCY["<b>Uses your connector</b><br/>Narrow or remove your own connection<br/>You cannot use the endpoint"]

    K -->|No| HIDDEN["Not visible to you"]

 

    class ALL,MINE good

    class USE good

    class AGENCY accent

    class HIDDEN muted

The third is the one people do not expect. If an owner puts your Xero connection on a profile you are not part of, that profile appears in your list marked Uses your connector. You cannot use the endpoint, rename it, or see who else is on it, but you can turn tools off on your own connection or take it off the profile entirely.

That is deliberate. You ran the consent, so it is your Xero account doing the work and your name on its audit trail. You also get an email whenever someone adds your connector to a profile, and that particular email cannot be switched off. See Your connectors in other people's profiles.

What a member sees elsewhere

  • Connectors — every connection in the workspace is listed, so you can tell what is already connected. You can only rename, retool, or disconnect the ones you authorised yourself.
  • Profiles — the three cases above. When you build one, you can only add connections you authorised. An owner or admin can add theirs to it for you.
  • Activity — calls you made, plus calls made through a connection you authorised. Owners and admins see the whole workspace.
  • Settings → Notifications — your own preferences, set per workspace. The account's email settings are owner only.
  • Billing — owner only. Members do not see the plan, the credit balance, or the monthly allowance.