ReferenceTeam
Team roles and permissions
Four roles exist: Owner, Admin, Member, and Billing Manager. A role sets what kinds of action a person may take. Access — which pages and accounts they may take those actions on — is a second, independent setting, and both must allow an action before it happens. Two roles force full-workspace access and cannot be narrowed.
Summary
Section titled “Summary”| Role | Can be invited | Access | Holds |
|---|---|---|---|
| Owner | No — ownership is transferred, never invited | Whole workspace, always | Everything, including billing |
| Admin | Yes | Whole workspace, forced | Everything except billing |
| Member | Yes | Scoped by default | Automations, comments, inbox, contacts, connecting accounts |
| Billing Manager | Yes | Scoped by default | Billing only |
Permissions by role
Section titled “Permissions by role”The app groups permissions into seven switches on the member drawer. Two of them are shown for information and cannot be changed on an individual.
| Switch | Owner | Admin | Member | Billing Manager | Adjustable per person |
|---|---|---|---|---|---|
| View Analytics | Yes | Yes | Yes | No | No |
| Moderate Comments | Yes | Yes | Yes | No | No |
| Inbox access | Yes | Yes | Yes | No | Yes |
| Manage Automations | Yes | Yes | Yes | No | Yes |
| Connect & Disconnect Social Accounts | Yes | Yes | Yes | No | Yes |
| Manage Team Members | Yes | Yes | No | No | Yes |
| View Billing & Payments | Yes | No | No | Yes | Yes |
A switch turned on for one person changes nothing for anybody else with the same role.
- Access: the whole workspace, always. Cannot be narrowed by anyone, including themselves.
- Exclusive to this role: dissolving the team, transferring ownership.
- Billing: yes. The team’s subscription belongs to the owner’s account.
- Leaving: impossible. An owner transfers ownership or dissolves the team.
- Removal: impossible. No role can remove the owner.
There is exactly one owner per team.
- Access: the whole workspace, forced. Assigning pages to an Admin is refused.
- Holds: every permission except billing.
- May act on: any non-owner, including other Admins — invite them, change their role, change their access, remove them.
- Billing: no. An Admin cannot see plans, payment methods, or invoices.
Promoting a scoped Member to Admin removes their page boundary. It is a widening of access, not only an addition of permissions.
Member
Section titled “Member”- Access: scoped by default, to whatever pages and accounts are assigned. Nothing assigned means nothing visible.
- Holds: automations, comment moderation, inbox, contacts, and connecting or disconnecting accounts.
- May act on: nobody. Members cannot invite, promote, or remove.
- Billing: no.
This is the working role. Every permission it holds still stops at the edge of its assigned pages.
Billing Manager
Section titled “Billing Manager”- Access: whatever it is set to. Unlike Owner and Admin this role forces nothing, so a demoted Admin keeps whole-workspace access. It makes little difference in practice, because the role holds no permission that acts on a page.
- Holds: billing only. Plans, payment methods, invoices, and the billing portal.
- May act on: nobody.
- Acts for: the team owner. A Billing Manager opening the portal or an invoice sees the owner’s, because a team’s billing belongs to the owner.
Access modes
Section titled “Access modes”| Mode | Meaning | Which roles |
|---|---|---|
| Whole workspace | Every page and account in the team, and every page added later | Owner and Admin, forced. Also available to Member and Billing Manager |
| Scoped | Only the pages and accounts explicitly assigned | Default for Member and Billing Manager |
An empty assignment set means the person sees nothing. It never means they see everything.
Assigning pages to a member switches them to scoped access if they were on whole-workspace access.
Account grants versus page grants
Section titled “Account grants versus page grants”Two separate kinds of assignment exist, and one does not imply the other.
| Grant | Authorizes |
|---|---|
| Account | Acting on that Facebook or Instagram account |
| Page | Acting on that page: its campaigns, comments, and inbox |
Acting on a page requires the page itself to be assigned. Some listings deliberately show both an account and its pages together, which is why a page can appear in a list that the member cannot then act on.
A dedicated Instagram account has no parent account and is only reachable through a page grant.
Who may act on whom
Section titled “Who may act on whom”| Action | Owner | Admin | Member | Billing Manager |
|---|---|---|---|---|
| Invite a person | Yes | Yes | No | No |
| Resend or revoke an invitation | Yes | Yes | No | No |
| Change a non-owner’s role | Yes | Yes | No | No |
| Change a non-owner’s access | Yes | Yes | No | No |
| Remove a non-owner | Yes | Yes | No | No |
| Rename the team | Yes | Yes | No | No |
| Transfer ownership | Yes | No | No | No |
| Dissolve the team | Yes | No | No | No |
| Read the activity log | Yes | Yes | Yes | Yes |
Nobody may act on the owner through these actions, and nobody may remove themselves — leaving is a separate action on your own membership.
Invitable roles
Section titled “Invitable roles”Admin, Member, and Billing Manager. Owner is not on the list; the role moves only by transferring ownership to an existing member.
- One account belongs to at most one team. Someone already in a team, or owning one, cannot be invited until they leave or dissolve it.
- A role that forces whole-workspace access drags access with it on every role change, in both directions.
- Transferring ownership demotes the previous owner to Admin with whole-workspace access, and moves the subscription to the new owner.
- A permission switch never widens access. Access is only widened by assigning pages, or by a role that forces whole-workspace access.
Related
Section titled “Related”- Work as a team — creating a team, inviting, and leaving.
- Limit a teammate to certain pages — assigning access in the app.
- Activity log actions — how each of these changes is recorded.
- Page permissions and tokens — the Facebook-side permissions, which are a separate matter.