Roles and permissions

The four workspace roles, what each may do, what you see instead of a control you lack, inviting teammates and how seats are counted.

Four workspace roles. Your role is per workspace — you can be an owner in one and a client in another.

RoleIn one line
OwnerEverything, including billing and deleting the workspace.
AdminEverything except billing.
AgentWorks the inbox and builds automations. No connections, no billing.
ClientReads the inbox, replies as a human, and can pause the AI. Can't change automations, connections or billing.

Who can do what

CapabilityOwnerAdminAgentClient
Manage commerce (Stripe keys)
Manage billing
Manage connections (connect/disconnect a channel)
Manage workspace (name, timezone, notifications)
Send broadcast
Manage agent (master switch, voice, goals, guardrails, knowledge)
Manage automations (automations, flows, rules, contacts, tags, fields, sequences, saved segments, products, media, keywords, workspace variables, main menu)
Pause agent (stand the AI down)

Everything not in this table — reading the Inbox, replying as a human, viewing Contacts, Analytics, the Activity log, the AI Playground — is open to every role.

The agent/client inversion

Look at the last two rows. On the Contacts page an agent sees the tag and field controls but no pause control, while a client sees the pause control but no tag controls.

That is deliberate, and it is the whole reason pause_agent exists as its own capability. A client who has to be able to say "stop replying as me, now" gets exactly that — and not the ability to change your timezone or silence your notification emails, which manage_workspace would have handed them too.

client is also strictly less privileged than agent everywhere else, which is why an admin who may already hand out agent can safely hand out client.

What you see instead of a control you lack

The product hides controls rather than letting you click them and be refused — but it always shows the state, and it usually explains the absence:

  • On Contacts, one sentence stands where Add contact would be, so you meet the reason at the first control you'd reach for.
  • On the channel cards, the connection status stays visible for everyone; only the Connect / Disconnect button goes.
  • On the Agent page, the master switch's On / Off state is shown to everyone — someone working the Inbox needs to know whether the AI is also answering — but only owner/admin get the toggle.
  • On Media library, the two possible reasons are kept apart: a plan limit ("upgrade") and a role limit ("ask an owner") point at different next steps.

Hiding is not the security boundary. Every write is re-checked on the server, so a control you can't see is also a control you can't invoke by any other route. The hiding exists so you aren't clicking things that always bounce.

Inviting

  • Owners may invite Admins, Agents and Clients; Admins may invite Agents and Clients. Nobody can invite an Owner — ownership comes only from creating a workspace.
  • Choosing a role is a Pro (and Agency) feature. Below Pro, every invite carries the Agent role — picking Admin or Client is refused with an upgrade message.
  • Client appears in the picker only where the client role is enabled for the deployment; if you don't see it, it isn't switched on for your account yet.
  • Owners may remove anyone except the last owner; admins may remove agents and clients. A workspace must always keep at least one owner — the last owner cannot leave or be removed.

Steps: settings.md.

Seats

A seat is a person, including you — and a pending invite holds one.

PlanSeats (incl. owner)Invitable teammates
Free10
Starter10
Growth21
Pro109
Agencyunlimitedunlimited

Organization roles are different

If your account is in an organization, it also has org-level roles — Owner, Admin, Analyst — which govern access across the organization's workspaces. They are separate from the four workspace roles above.

Common questions

Which role should I give a VA who answers DMs? agent if they should also build automations; client if they should only work the inbox and be able to pause the AI.

Which role for a client who wants to watch their own account? client. They can read everything, reply as a human, and stop the AI — and cannot change your automations, connections or billing.

Why can an agent not turn the AI on? agent is the role invites hand out by default. Without that gate, a support hire could turn the AI on for your whole customer base on their first day.

Why can't I connect Instagram? manage_connections — owner or admin only.

Can I make my own custom role? No. The four roles are fixed.

Try HyperDM for free

50 free conversations a month, no card. Connect Instagram and follow the guide you just read.

Get startedNO CARD · LIVE IN 10 MINUTES · CANCEL ANYTIME