Roles & permissions
Permission list
| Key | Description | Menu |
|---|---|---|
dashboard.view | View the dashboard | Dashboard |
interaction.view | View the Interaction menu | Interaction |
interaction.reply | Reply to conversations (attachments & quick replies) | Interaction |
interaction.manage | Change status, category, labels, tags, notes; assign | Interaction |
interaction.escalate | Created an escalation ticket | Interaction |
ticket.view_assigned | View tickets they follow or are assigned to | Ticket |
ticket.view_all | View all workspace tickets | Ticket |
ticket.manage | Change ticket status/priority, add/remove participants | Ticket |
report.view | View the Reports menu | Reports |
report.export | Export CSV | Reports |
ai.use | Use Summarize & Draft reply (Pro only) | AI |
settings.channels | Connect/disconnect Threads accounts | Threads channels |
settings.master_data | Manage categories, labels, tags, quick replies | Master data |
settings.members | Invite members, change roles, deactivate members | Users |
settings.roles | Manage roles | Users |
settings.billing | Plan, invoices & payments | Plan & billing |
settings.audit | View the workspace audit log | Audit log |
settings.workspace | General settings & workspace profile | Settings |
settings.api | Manage API keys (Pro only) | Settings |
Default roles
Created automatically when a workspace is created. All except Owner can be edited, duplicated, or deleted (when not in use).
| Role | Permissions |
|---|---|
| Owner | All permissions. Only the workspace owner has this role; it can't be changed. |
| Leader | View the dashboard, View the Interaction menu, Reply to conversations (attachments & quick replies), Change status, category, labels, tags, notes; assign, Create escalation tickets, View all workspace tickets, Change ticket status/priority, add/remove participants, View the Reports menu, Export CSV, Use Summarize & Draft reply, Manage categories, labels, tags, quick replies |
| Tier 1 (Agent Interaction) | View the dashboard, View the Interaction menu, Reply to conversations (attachments & quick replies), Change status, category, labels, tags, notes; assign, Create escalation tickets, Use Summarize & Draft reply |
| Tier 2 (Agent Tiket) | View tickets they follow or are assigned to |
Threads account access
Besides the role, each member can be limited to specific Threads accounts ("All accounts" or selected accounts). Conversations from other accounts don't appear anywhere for that member: Interaction, Dashboard, Reports, notifications, and the ticket list (unless they're a participant in the ticket).
Example setups
A shop with one admin and one warehouse team
- The CS admin uses Tier 1: replies, changes statuses, escalates.
- The warehouse team uses Tier 2: sees only the tickets assigned to them, joins the discussion, and sends feedback to the conversation. Tier 2 still sees the original conversation on the ticket page without Interaction access.
An agency managing several client accounts
- A Leader per client with access to that client's Threads account only, plus Reports and Export CSV.
- Tier 1 agents limited to the accounts they handle.
- A new "Finance" role with Plan & billing access only (only the Owner can grant this access).
Security rules
- Opening a URL directly without the permission shows a 403 page (or a 403 error in the API).
- Except for the Owner, whoever manages roles/members can only grant access they have themselves, can't change members with higher access, and can't change their own role.
- Role changes take effect immediately; members don't need to sign in again.