Platform
Workspace Roles & Permissions
A simple guide to operational eligibility for Viewer, Member, Admin, and Owner roles.
Docs Summary
- What this page explains: The exact operational eligibility and RLS enforcement for Viewer, Member, Admin, and Owner roles.
- Who should use it: Workspace administrators, security auditors, and team members.
- Related MailSend feature: Workspace team settings and access control
- Common use cases: Setting up team roles, auditing permissions, understanding RLS rules
- Related docs: Introduction, API Reference
Every member in your workspace gets one of four roles. These roles determine exactly what tools, endpoints, and data they can touch. Here is a quick breakdown:
| Role | Access Level | Perfect For |
|---|---|---|
| Viewer | Read-only stats & logs | Auditors, clients, or team members who just need to watch analytics without changing settings. |
| Member | Composing & Operations | Marketers, writers, and support agents who compose templates, schedule campaigns, and manage contacts. |
| Admin | Full management & config | Tech leads and workspace admins who configure domains, rotate API keys, set up webhooks, and upgrade plans. |
| Owner | Absolute root access | The workspace creator. Has total admin control, plus the exclusive power to delete the workspace. |
The Big Feature Grid
Here is exactly which actions each role can trigger:
| Feature Area | Action | Viewer | Member | Admin | Owner |
|---|---|---|---|---|---|
| Workspace Settings | Rename Workspace | ❌ | ❌ | ✅ | ✅ |
| Workspace Settings | Delete Workspace | ❌ | ❌ | ❌ | ✅ |
| Team Management | View Team Members | ✅ | ✅ | ✅ | ✅ |
| Team Management | Invite / Add Members | ❌ | ❌ | ✅ | ✅ |
| Team Management | Change Roles / Remove Members | ❌ | ❌ | ✅ | ✅ |
| Sending Domains | View Verification Status | ✅ | ✅ | ✅ | ✅ |
| Sending Domains | Add New Domain | ❌ | ❌ | ✅ | ✅ |
| Sending Domains | Verify DNS / DKIM | ❌ | ❌ | ✅ | ✅ |
| Sending Domains | Delete Verified Domain | ❌ | ❌ | ❌ | ✅ |
| Integrations | View API Keys & Webhooks | ✅ | ✅ | ✅ | ✅ |
| Integrations | Create/Edit/Revoke API Keys | ❌ | ❌ | ✅ | ✅ |
| Integrations | Create/Edit/Revoke Webhooks | ❌ | ❌ | ✅ | ✅ |
| Billing & Plans | Access Billing Dashboard | ❌ | ❌ | ✅ | ✅ |
| Billing & Plans | Upgrade/Downgrade Subscription | ❌ | ❌ | ✅ | ✅ |
| Composing & Sends | Send Single Email (/compose) | ❌ | ✅ | ✅ | ✅ |
| Composing & Sends | View Send Logs / History | ✅ | ✅ | ✅ | ✅ |
| Composing & Sends | Inspect Audit Timeline / Events | ✅ | ✅ | ✅ | ✅ |
| Templates | View Templates | ✅ | ✅ | ✅ | ✅ |
| Templates | Create/Edit/Delete Templates | ❌ | ✅ | ✅ | ✅ |
| Campaigns & Broadcasts | Create/Edit/Schedule Campaign | ❌ | ✅ | ✅ | ✅ |
| Campaigns & Broadcasts | Launch or Cancel Campaign | ❌ | ✅ | ✅ | ✅ |
| Contacts & Lists | View Contacts & Lists | ✅ | ✅ | ✅ | ✅ |
| Contacts & Lists | Add/Import/Delete Contacts | ❌ | ✅ | ✅ | ✅ |
| Contacts & Lists | Add/Delete Contact Lists | ❌ | ✅ | ✅ | ✅ |