heedbackdocs

Roles and permissions

Everyone you invite gets a role, and the role decides what they can do. Roles are free on every plan, including Free — seats are free here, so the whole company can be in the workspace, and roles are how you decide who can speak to your users.

Set them from Members in your account.

The four roles

RoleCan do
OwnerEverything, including billing and handing the workspace to someone else
AdminEverything except billing and transferring the workspace
MemberWrite anything; publish nothing your users will see
ViewerRead everything; change nothing

New teammates join as Member unless you pick something else.

What "Member" really means

This is the role most of your team should have, and the line it draws is the point of the whole system: a member can write, and cannot publish.

They can create and edit posts, boards, comments, changelog entries, surveys and in-app messages. They cannot publish a changelog entry, activate a survey, send a survey invitation, or publish a hintuition experience — every one of those puts something in front of your own users.

They also cannot invite people, change roles, manage API keys, or change how the workspace works (custom fields, statuses, private-board settings, Slack, or the customer-identity secret). Generating or rotating that secret, and flipping the "reject unsigned calls" switch, are owner and admin only — the same credential-management permission that guards your Slack connection. Everyone can still read the People list.

What "Viewer" is for

Someone who needs to see what's going on and shouldn't be able to change it — a stakeholder, a new starter in their first week, someone from another team.

A viewer can read every board, post, changelog and survey. They can't write a comment, and they can't see billing amounts. That last one is deliberate: read-only isn't the same as need-to-know.

Rules we enforce, and why

You can't change your own role. Otherwise the whole thing is decoration.

Only an owner can make — or unmake — another owner. An admin creating an owner would be creating billing access; an admin demoting one could remove the person who appointed them.

A workspace always keeps at least one owner. The last owner can't be demoted or removed. A workspace with no owner has nobody who can pay for it or hand it over, and there's no way back from that.

Role changes take effect immediately — on that person's very next action, not at their next sign-in.

Every role change is recorded in your audit log, with who changed it, whose role changed, and what it went from and to.

If something is refused

You'll see a short message saying you don't have permission. Ask an owner or admin to change your role — the answer is always a role, never a hidden setting.

If you think a role is drawn in the wrong place — someone needs one specific thing their role doesn't cover — tell us. Narrower, per-board permissions are on the way, and the cases you hit are what shapes them.