Members and roles
A workspace holds one company's records, people and settings. People in one workspace never see another workspace's data.
Inviting people
Admins invite people in Settings > Members. Enter an email address and pick a role:
| Role | What they can do |
|---|---|
| Viewer | Read what they have access to. |
| Editor | Create and change records. |
| Admin | Everything an editor can, plus manage people and settings. |
Tick Works at the company to add the person to HR as an employee when they accept. Pending invitations are listed on the same page, where you can resend or revoke them.
Custom roles
When the three roles are too broad, build your own in Settings > Permissions. A custom role starts from viewer, editor or admin and adds exactly the capabilities you choose, for shipped modules and your add-ons. Assign it to members on the same page.
You can also give one person view or edit access to a single kind of record without changing their role.
Approvals and separation of duties
- Settings > Approvals sets which records need approval and who approves them. Admins can apply the recommended policies in one step. Anyone can hand their own approvals to a colleague while they are away, and take them back.
- Settings > SoD Rules (separation of duties) lists pairs of duties one person may not hold together, and shows any violations.
- Settings > Roles shows the authorities in your workspace and who holds them.
The same rules apply to AI agents: an agent can only see and do what its role allows. See Agents and Needs you.