Roles and permissions
The four roles you can give a teammate, a full list of what each one can and cannot do, and how to choose the right role for a new person.
- Who
- Owners and admins deciding who can do what
- Plan
- All plans. How many people you can add depends on your plan.
- Role
- Every role can see the team list. Only an Owner or an Admin can change a role.
Before you start
- A signed-in account with access to **Dashboard → Team**
Everyone in your workspace has exactly one role, and that role decides what they are allowed to do. There are four roles you can assign — Owner, Admin, Agent and Viewer — and they build on each other. An Agent can do everything a Viewer can, an Admin everything an Agent can, and an Owner everything an Admin can plus one thing more.
The four roles
| Role | What it is for | Give it to |
|---|---|---|
| Owner | Full control of the workspace, including asking for the workspace to be deleted. | The person who owns the business account. A workspace can have several owners and must always keep at least one. |
| Admin | Everything an Owner can do except requesting deletion: settings, billing, WhatsApp, business knowledge and the team. | A manager, or whoever set OMAI up and looks after it day to day. |
| Agent | Works in the inbox — replies to customers, takes over from the assistant, assigns and resolves conversations. | Customer-service staff who answer messages but should not change how the business is configured. |
| Viewer | Read-only. Sees conversations, business knowledge, reports, billing figures and the team list, and changes nothing. | An accountant, an external consultant, or someone still being trained. |
The role is stored per workspace, not per person. The same email address can be an Owner in one workspace and an Agent in another.
What each role can do
This is the complete list, taken from the permission rules the product enforces. A ✓ means the role is allowed; a dash means the action is refused with a permission error.
| Capability | Viewer | Agent | Admin | Owner |
|---|---|---|---|---|
| Read conversations and message history | ✓ | ✓ | ✓ | ✓ |
| Reply to a customer and take over a conversation | — | ✓ | ✓ | ✓ |
| Assign a conversation to a teammate | — | ✓ | ✓ | ✓ |
| Pause or resume the assistant in a conversation | — | ✓ | ✓ | ✓ |
| Mark a conversation resolved | — | ✓ | ✓ | ✓ |
| Add an internal note to a conversation | — | ✓ | ✓ | ✓ |
| Read the business knowledge | ✓ | ✓ | ✓ | ✓ |
| Add, edit or delete business knowledge | — | — | ✓ | ✓ |
| See the billing screen, the plan and the invoices | ✓ | ✓ | ✓ | ✓ |
| Start a subscription, change plan, change the payment card | — | — | ✓ | ✓ |
| See the team list | ✓ | ✓ | ✓ | ✓ |
| Add a team member | — | — | ✓ | ✓ |
| Change a member’s role | — | — | ✓ | ✓ |
| Remove a member | — | — | ✓ | ✓ |
| Read message templates | ✓ | ✓ | ✓ | ✓ |
| Create, edit or delete message templates | — | — | ✓ | ✓ |
| See reports | ✓ | ✓ | ✓ | ✓ |
| Change assistant settings | — | — | ✓ | ✓ |
| Pause or resume the assistant for the whole organization | — | — | ✓ | ✓ |
| Open the setup steps and change anything in them | — | — | ✓ | ✓ |
| Confirm authority and connect or remove a WhatsApp number, buy a number | — | — | ✓ | ✓ |
| Change workspace settings — business details, language, timezone, hours, services, FAQ, policies | — | — | ✓ | ✓ |
| Read the audit log | — | — | ✓ | ✓ |
| Export the workspace data as JSON | — | — | ✓ | ✓ |
| Accept the Terms on behalf of the organization | — | — | ✓ | ✓ |
| Request deletion of the whole workspace | — | — | — | ✓ |
One line in that table surprises people: a Viewer and an Agent can see the billing screen, including the plan, the usage figures and the invoice list. They cannot start, change or cancel anything there. If billing figures should not be visible to a person at all, do not add them to the workspace.
Extra rules on top of the table
Four rules sit above the permission list and cannot be worked around from the dashboard:
- Only an Owner can add a new member as an Owner, or raise an existing member to Owner. An Admin who tries gets “Only an owner can grant the owner role.”
- The last Owner cannot be demoted or removed. The attempt is refused with “Cannot remove the last owner of the organization.” To hand the business over, first make the other person an Owner, then change or remove the original one.
- While a workspace has two or more Owners, an Admin can demote or remove one of them. Give the Admin role only to people you would trust with that.
- Platform Admin is not a role you can assign. It is an internal OMAI operator identity, and the product refuses to write it to a member record.
Which role to give a new person
- They will answer customer messages and nothing else → Agent. This is the shipped default on the invite form and the right answer most of the time.
- They will also maintain the price list, the FAQ, the assistant’s settings or the WhatsApp connection → Admin.
- They only need to look — reporting, bookkeeping, an outside adviser → Viewer.
- They are a business partner who should be able to close the account → Owner.
What each role actually sees
Permissions are enforced on our servers when an action runs, so a control that is out of sight is a courtesy and never the lock. On top of that, the dashboard tries not to advertise a dead end. A lower role therefore has a genuinely shorter menu: the two screens an Agent and a Viewer cannot use at all — Assistant Settings and Audit Log — are left out of the sidebar for them, and reaching either from a bookmark or an old link produces a short explanation rather than a failure. On Team, a role that cannot manage members gets a read-only roster with no invite form and no per-person controls; and even an Admin is not offered a role change or a removal on the row of someone who outranks them.
Where a refusal is shown inline — the invite form, or a role change the ranking rules do not allow — it is a plain sentence in your own language saying what was refused and who can do it instead. It does not print an internal permission name; if you ever see one, that is worth reporting to us.
The Platform Admin badge
If you ever see Platform Admin in a role list, it belongs to OMAI’s own operator access, which is separate from your workspace roles and is used for support and platform administration. It is never granted through the Team screen, and it carries none of the workspace permissions in the table above. What operators can reach, and how it is recorded, is described in Who can access your data.
Where role changes are recorded
Adding a member, changing a role and removing a member each write an entry to the audit log with who did it, when, and the old and new role. An Admin or an Owner can read it on Dashboard → Audit Log; see The audit log.
Common questions
Can I create my own role with my own set of permissions?
No. The four roles are fixed, and their permissions cannot be edited. Pick the closest one.
Can two people be Owner?
Yes, and that is how ownership is transferred: an existing Owner raises the second person to Owner, and after that either of them can change or remove the other. There is no separate “transfer ownership” button.
Does a role change sign the person out?
No. The new role applies from their next page load, because the role is read from the database on every request. They do not have to sign out and back in.
I changed a role and nothing confirmed it.
That is expected. The dropdown keeps the new value and no confirmation message is shown. Reload the Team screen to check, or look for the role_change entry in the audit log.
Can a Viewer read customers’ message content?
Yes. Read access to conversations includes the messages inside them. A Viewer is a read-only role, not a redacted one.
