Skip to content

Users, Roles, and Teams

Open Settings → Users (/settings/users) to control who belongs to the organization and what each person can do. The old /admin/users address only redirects to this page.

People with users.view can read the list. Changing members, invitations, or roles requires access_control.manage; the organization owner also has this access.

The Users tab combines active, inactive, plan-restricted members and pending invitations. The table shows name, email, last login, role or team, status, and the actions menu.

The other tabs depend on the organization’s configuration:

  • with granular permissions enabled, access administrators see Roles;
  • in the legacy model, access administrators see Teams;
  • people with read-only permission see Users only, with mutation controls disabled.

Search by name or email. The Status filter offers All, Active, Inactive, and Pending. The last filter changes with the organization’s model: Role in the granular model or Team in the legacy model.

Invitations that have not been accepted appear in the same list with the Pending invite badge and Pending status. They cannot be included in bulk actions.

In the current model, a person can have more than one role. Permissions from all selected packages are added together:

RoleIntended forImportant limit
AdministratorPeople who must manage agents, channels, conversations, contacts, knowledge, reports, API, and the teamCannot manage billing, close the organization, or transfer ownership
AI AgentsPeople who create, configure, connect, and publish AI AgentsCannot handle conversations or manage contacts, the team, API, webhooks, or reports
SupportPeople working with CRM, conversations, contacts, quick replies, and emailsCannot create AI Agents, connect channels, delete knowledge bases, or view reports
CollaboratorPeople using the Hub, Rooms, and internal meetingsCannot access customer conversations, contacts, AI Agents, or settings
CustomOne person who needs individually selected permissionsBelongs to that person only; it is not a shared package

Open the Roles tab to read the complete summary of what each package can and cannot do. Custom starts with Rooms access and opens a capability checklist for individual selection.

The Owner is not a selectable role. Each organization has exactly one owner, with full access and exclusive authority over billing, organization closure, and ownership transfer.

  1. On the Users tab, select Invite.
  2. Enter Name and Email.
  3. Select one or more Roles. For a specific combination, select Custom and check the required permissions.
  4. Select Send Invite.

A valid pending invitation counts against the plan limit. When the limit is reached, Invite is disabled and the page offers seat management or an upgrade.

The person receives an email and must complete the flow in Accept an invitation. From the pending invitation’s menu, select Resend invite or Cancel invite.

Open a member’s three-dot menu and select Edit. You can:

  • change the display name; the sign-in email is read-only;
  • change one or more roles and, for Custom, review capabilities;
  • suspend access;
  • remove the person from the organization.

The owner’s role cannot be changed and the owner cannot be removed through this flow. In the owner’s row menu, only the owner sees Transfer ownership. The destination must be an active administrator; after the transfer, the previous owner becomes an administrator.

Select active members in the first column to display the selection bar. In the granular model, Change role applies one of the four predefined packages to everyone selected; Custom is not available in bulk. You can also Suspend the selected members.

In the legacy model, the actions are Change Role, Change Team, and Suspend. Bulk promotion to administrator and larger suspension batches require additional confirmation.

When the plan has a user limit, the counter includes current members and pending invitations. Manage seats lets you choose which members occupy the available seats. The owner is always active; anyone left out keeps their account, receives the No plan seat badge, and regains access when a seat is released.

Organizations that have not migrated to granular roles see the Teams tab. Each team can control agent categories, agentless conversations, access to the model selector, and allowed models. Teams can also be created, edited, deleted, and viewed as a list or cards.

Do not create a team to represent a role in the granular model. Assign packages directly to the person or use Custom instead.

  • Grant only the required roles; packages accumulate permissions.
  • Reserve Administrator for people who actually manage access and organization settings.
  • Use Custom for individual exceptions, not as the default role.
  • Review pending invitations, inactive people, and plan seats regularly.
  • Transfer ownership before the current owner leaves the organization.
  • Use individual corporate emails and never share accounts.