OmniBrand
☰

Roles and permissions: what each role can do

The six roles (Owner, Admin, Editor, Reviewer, Viewer, Agent), the tasks each holds by default, and how to add or remove a task for one person.

Every member has one Role per workspace, and each role comes with a set of tasks. An owner or admin can add a task to one person or take one away, with Edit access on Members.

The roles

  • Owner: full access, including billing and ownership. Only an owner can make someone else an owner, change or remove an owner, archive or delete the workspace. The owners of the account's first workspace are the only ones who can delete the whole account.
  • Admin: full access to every area of this workspace: settings, brand, accounts, members, AI and API keys, company details. An admin cannot touch owners.
  • Editor: creates and publishes content, replies in the Inbox.
  • Reviewer: approves content and replies in the Inbox.
  • Viewer: read-only across the workspace.
  • Agent (inbox only): reads, replies, adds notes and blocks or marks spam in the Inbox. An agent sees only the Inbox, the Team chat, Bookings, Accounts (to add their own mailbox), Your account and Help; any other page sends them back to the Inbox.

Tasks each role holds by default

Owner and Admin hold every task below. - Inbox, Read (see conversations assigned to them or unassigned): Editor, Reviewer, Viewer, Agent. - Inbox, Reply (send replies to customers): Editor, Reviewer, Agent. - Inbox, Notes (add internal notes teammates can see): Editor, Reviewer, Agent. - Inbox, Assign (assign conversations to teammates): owner and admin only by default. - Inbox, Delete (delete conversations and messages): owner and admin only by default. - Inbox, Block and spam (block a contact or mark them as spam, and undo either; does not allow deleting): Agent. A member who was given Delete also holds Block and spam, because blocking used to be part of Delete; untick Block and spam to take it away. Unticking Delete does not remove Block and spam. - Inbox, View all (see every conversation, including ones assigned to others): owner and admin only by default. - Inbox, Saved replies (create and manage saved replies): Editor. - Content, View (see drafts, the calendar and records): Editor, Reviewer, Viewer. - Content, Create (write and edit content): Editor. - Content, Approve (approve or reject content awaiting review): Reviewer. - Content, Publish (schedule and publish to accounts): Editor. - Insights, Analytics (view performance analytics): Editor, Reviewer, Viewer. - Insights, Market Watch (see Market Watch observations and opportunities): Editor, Reviewer, Viewer. - Insights, Manage Market Watch (add sources and tasks, run scans): Editor. - Contacts, Manage contacts (edit contacts, their custom fields and consent; merge contacts; manage the custom field list; move leads): Editor. - Contacts, Import contacts (bring in contacts from a CSV or Excel file with Contacts → Import, and declare the consent the people on it gave): owner and admin only by default. - Contacts, Export contacts (download the contact list, or a WhatsApp broadcast's recipients with Export CSV on its results, as a CSV file with names, numbers and e-mails): owner and admin only by default. Before this task existed Editors could export; give it back to an Editor with Edit access if they need it. - Campaigns, Manage WhatsApp templates (create, submit, edit and delete WhatsApp message templates, upload their sample media, unpause them and send test messages to the workspace's test numbers): Editor. Everyone can still see templates and pick one in the Inbox. Campaigns, Manage ads (create Click-to-WhatsApp ads with the workspace's Meta ad account, start them - Meta then charges the ad account - and pause, resume and delete them; see Promote on WhatsApp): no role has it by default besides Owners and Admins; tick it for an Editor who should run ads. - Settings, brand approval, accounts and members are not a task you can hand out: they belong to the Owner and Admin roles. To let someone manage them, make them an Admin.

Step by step: change one person's tasks

  1. Open Settings, then Members (/app/settings/members).
  2. Click Edit access on the member (not shown for owners and admins, who always have everything).
  3. In "Give this person access to…", tick or untick tasks. Badges explain each line: Included in role (a default that is on), Added (on, beyond the role), Removed (a default you switched off).
  4. Click Save access. "Access updated for ..." confirms it.

Good to know

  • Unticking a default really removes it: an editor with Publish unticked cannot publish.
  • A Viewer cannot be given Reply, Notes, Assign, Block and spam or Delete in the Inbox: those boxes are not shown for a Viewer, because the Inbox refuses a Viewer on those actions whatever the ticks say. To let someone answer customers, make them an Agent, Reviewer or Editor.
  • Changing someone's role resets their tasks to the new role's own (see Members and invitations).
  • Some actions are tied to the Owner or Admin role itself, not to a task: inviting and removing members, changing roles, the workspace timezone and link tracking, AI keys, developer API keys, branding, company details, billing, approving the brand profile and reading the website into it. That is why the task list has no Settings box; a Settings task given to someone in the past no longer shows them the Settings pages, because every save there would be refused.
  • If someone cannot see a page or a button, see I cannot see a page or a button.

Related

Checked against the product on Sep 24, 2026

In this section: Settings

All articles