Roles and permissions
The four workspace roles, what each may do, what you see instead of a control you lack, inviting teammates and how seats are counted.
Four workspace roles. Your role is per workspace — you can be an owner in one and a client in another.
| Role | In one line |
|---|---|
| Owner | Everything, including billing and deleting the workspace. |
| Admin | Everything except billing. |
| Agent | Works the inbox and builds automations. No connections, no billing. |
| Client | Reads the inbox, replies as a human, and can pause the AI. Can't change automations, connections or billing. |
Who can do what
| Capability | Owner | Admin | Agent | Client |
|---|---|---|---|---|
| Manage commerce (Stripe keys) | ✅ | — | — | — |
| Manage billing | ✅ | — | — | — |
| Manage connections (connect/disconnect a channel) | ✅ | ✅ | — | — |
| Manage workspace (name, timezone, notifications) | ✅ | ✅ | — | — |
| Send broadcast | ✅ | ✅ | — | — |
| Manage agent (master switch, voice, goals, guardrails, knowledge) | ✅ | ✅ | — | — |
| Manage automations (automations, flows, rules, contacts, tags, fields, sequences, saved segments, products, media, keywords, workspace variables, main menu) | ✅ | ✅ | ✅ | — |
| Pause agent (stand the AI down) | ✅ | ✅ | — | ✅ |
Everything not in this table — reading the Inbox, replying as a human, viewing Contacts, Analytics, the Activity log, the AI Playground — is open to every role.
The agent/client inversion
Look at the last two rows. On the Contacts page an agent sees the tag and field controls but no pause control, while a client sees the pause control but no tag controls.
That is deliberate, and it is the whole reason pause_agent exists as its own capability. A client who has to be able to say "stop replying as me, now" gets exactly that — and not the ability to change your timezone or silence your notification emails, which manage_workspace would have handed them too.
client is also strictly less privileged than agent everywhere else, which is why an admin who may already hand out agent can safely hand out client.
What you see instead of a control you lack
The product hides controls rather than letting you click them and be refused — but it always shows the state, and it usually explains the absence:
- On Contacts, one sentence stands where Add contact would be, so you meet the reason at the first control you'd reach for.
- On the channel cards, the connection status stays visible for everyone; only the Connect / Disconnect button goes.
- On the Agent page, the master switch's On / Off state is shown to everyone — someone working the Inbox needs to know whether the AI is also answering — but only owner/admin get the toggle.
- On Media library, the two possible reasons are kept apart: a plan limit ("upgrade") and a role limit ("ask an owner") point at different next steps.
Hiding is not the security boundary. Every write is re-checked on the server, so a control you can't see is also a control you can't invoke by any other route. The hiding exists so you aren't clicking things that always bounce.
Inviting
- Owners may invite Admins, Agents and Clients; Admins may invite Agents and Clients. Nobody can invite an Owner — ownership comes only from creating a workspace.
- Choosing a role is a Pro (and Agency) feature. Below Pro, every invite carries the Agent role — picking Admin or Client is refused with an upgrade message.
- Client appears in the picker only where the client role is enabled for the deployment; if you don't see it, it isn't switched on for your account yet.
- Owners may remove anyone except the last owner; admins may remove agents and clients. A workspace must always keep at least one owner — the last owner cannot leave or be removed.
Steps: settings.md.
Seats
A seat is a person, including you — and a pending invite holds one.
| Plan | Seats (incl. owner) | Invitable teammates |
|---|---|---|
| Free | 1 | 0 |
| Starter | 1 | 0 |
| Growth | 2 | 1 |
| Pro | 10 | 9 |
| Agency | unlimited | unlimited |
Organization roles are different
If your account is in an organization, it also has org-level roles — Owner, Admin, Analyst — which govern access across the organization's workspaces. They are separate from the four workspace roles above.
Common questions
Which role should I give a VA who answers DMs? agent if they should also build automations; client if they should only work the inbox and be able to pause the AI.
Which role for a client who wants to watch their own account? client. They can read everything, reply as a human, and stop the AI — and cannot change your automations, connections or billing.
Why can an agent not turn the AI on? agent is the role invites hand out by default. Without that gate, a support hire could turn the AI on for your whole customer base on their first day.
Why can't I connect Instagram? manage_connections — owner or admin only.
Can I make my own custom role? No. The four roles are fixed.
More in Account & billing
- SettingsAll nine settings tabs: Channels, Main menu, Commerce, Billing & usage, Refer & earn, Team & roles, Workspace, Notifications and Security.Read
- Plans and billingEvery plan and what it includes, what each gate actually does, how overage protection works, and how to upgrade, downgrade or pause billing.Read
- OrganizationThe agency surface: client workspaces, pooled conversations, who pays, deploying a recipe to every client at once and the client report.Read
Try HyperDM for free
50 free conversations a month, no card. Connect Instagram and follow the guide you just read.