Roles, assignments, and support viewing

Last verified 2026-07-23

Workspace roles

  • Workspace admin: manages the workspace, Users, paid Seats, Connections, settings, and workspace-wide product areas.
  • Manager: sees the team and customer scope granted by the current role and feature gates.
  • Member: operates only the paid Seats, Connections, customers, and records assigned to that User.
  • VA/BDR Operator: works the assigned outreach scope without becoming the customer, workspace owner, or sales rep.
  • Client portal user: sees only the approved read-only customer view, never the operator workspace.

Platform and Reseller access

A platform support User or Reseller can enter only a workspace their current grant allows. The workspace id is rechecked on the server; a browser link or remembered cookie is never enough.

Support viewing

Support viewing is visibly separate from the workspace's own session. It can inspect approved screens for support, but sensitive or durable work such as activation, provider actions, AI spend, report changes, document changes, asset downloads, and customer support tickets remains blocked where the product marks it read only.

Hidden navigation is not the security boundary. Pages, server actions, route handlers, exports, and database access recheck workspace, role, and assignment.
Was this helpful?

Still stuck? hello@klosent.com. A human reads every message.