Account & Security
Agent permissions: giving each person the right access
Updated 2026-08-16
Roles set the baseline (owner, admin, agent) and permissions fine-tune it per person. You manage them in Settings > Team, on each member.
What you can grant or withhold: the ticket inbox, reports and analytics, the knowledge base, the customer portal and chat widget settings, the mailbox connection, automation and CSAT, team chat, billing and plans, and the individual settings sections.
How it behaves:
- Permissions are fail-closed. If a permission is not explicitly granted, the section is hidden and the underlying action is refused by the server, not only by the interface.
- Owners always keep full access, including billing, so a workspace can never lock itself out.
- Changes take effect on the agent's next page load; nobody has to be re-invited.
Removing a member deletes their access completely. If you invite the same address again, they receive a fresh invitation and set a new password.

