---
title: "Team roles and permissions"
description: "Every team role, the permissions it carries, the access it forces, and the rules governing who may invite, promote, remove, or reassign whom."
canonical: https://docs.afp.monster/reference/team-roles
updated: 2026-08-19
pageType: reference
---

Four roles exist: Owner, Admin, Member, and Billing Manager. A role sets what kinds of action a person may take. Access — which pages and accounts they may take those actions on — is a second, independent setting, and both must allow an action before it happens. Two roles force full-workspace access and cannot be narrowed.

## Summary

| Role | Can be invited | Access | Holds |
|---|---|---|---|
| Owner | No — ownership is transferred, never invited | Whole workspace, always | Everything, including billing |
| Admin | Yes | Whole workspace, forced | Everything except billing |
| Member | Yes | Scoped by default | Automations, comments, inbox, contacts, connecting accounts |
| Billing Manager | Yes | Scoped by default | Billing only |

## Permissions by role

The app groups permissions into seven switches on the member drawer. Two of them are shown for information and cannot be changed on an individual.

| Switch | Owner | Admin | Member | Billing Manager | Adjustable per person |
|---|---|---|---|---|---|
| View Analytics | Yes | Yes | Yes | No | No |
| Moderate Comments | Yes | Yes | Yes | No | No |
| Inbox access | Yes | Yes | Yes | No | Yes |
| Manage Automations | Yes | Yes | Yes | No | Yes |
| Connect & Disconnect Social Accounts | Yes | Yes | Yes | No | Yes |
| Manage Team Members | Yes | Yes | No | No | Yes |
| View Billing & Payments | Yes | No | No | Yes | Yes |

A switch turned on for one person changes nothing for anybody else with the same role.

## Owner

- **Access:** the whole workspace, always. Cannot be narrowed by anyone, including themselves.
- **Exclusive to this role:** dissolving the team, transferring ownership.
- **Billing:** yes. The team's subscription belongs to the owner's account.
- **Leaving:** impossible. An owner transfers ownership or dissolves the team.
- **Removal:** impossible. No role can remove the owner.

There is exactly one owner per team.

## Admin

- **Access:** the whole workspace, forced. Assigning pages to an Admin is refused.
- **Holds:** every permission except billing.
- **May act on:** any non-owner, including other Admins — invite them, change their role, change their access, remove them.
- **Billing:** no. An Admin cannot see plans, payment methods, or invoices.

Promoting a scoped Member to Admin removes their page boundary. It is a widening of access, not only an addition of permissions.

## Member

- **Access:** scoped by default, to whatever pages and accounts are assigned. Nothing assigned means nothing visible.
- **Holds:** automations, comment moderation, inbox, contacts, and connecting or disconnecting accounts.
- **May act on:** nobody. Members cannot invite, promote, or remove.
- **Billing:** no.

This is the working role. Every permission it holds still stops at the edge of its assigned pages.

## Billing Manager

- **Access:** whatever it is set to. Unlike Owner and Admin this role forces nothing, so a demoted Admin keeps whole-workspace access. It makes little difference in practice, because the role holds no permission that acts on a page.
- **Holds:** billing only. Plans, payment methods, invoices, and the billing portal.
- **May act on:** nobody.
- **Acts for:** the team owner. A Billing Manager opening the portal or an invoice sees the owner's, because a team's billing belongs to the owner.

## Access modes

| Mode | Meaning | Which roles |
|---|---|---|
| Whole workspace | Every page and account in the team, and every page added later | Owner and Admin, forced. Also available to Member and Billing Manager |
| Scoped | Only the pages and accounts explicitly assigned | Default for Member and Billing Manager |

An empty assignment set means the person sees nothing. It never means they see everything.

Assigning pages to a member switches them to scoped access if they were on whole-workspace access.

## Account grants versus page grants

Two separate kinds of assignment exist, and one does not imply the other.

| Grant | Authorizes |
|---|---|
| Account | Acting on that Facebook or Instagram account |
| Page | Acting on that page: its campaigns, comments, and inbox |

Acting on a page requires the page itself to be assigned. Some listings deliberately show both an account and its pages together, which is why a page can appear in a list that the member cannot then act on.

A dedicated Instagram account has no parent account and is only reachable through a page grant.

## Who may act on whom

| Action | Owner | Admin | Member | Billing Manager |
|---|---|---|---|---|
| Invite a person | Yes | Yes | No | No |
| Resend or revoke an invitation | Yes | Yes | No | No |
| Change a non-owner's role | Yes | Yes | No | No |
| Change a non-owner's access | Yes | Yes | No | No |
| Remove a non-owner | Yes | Yes | No | No |
| Rename the team | Yes | Yes | No | No |
| Transfer ownership | Yes | No | No | No |
| Dissolve the team | Yes | No | No | No |
| Read the activity log | Yes | Yes | Yes | Yes |

Nobody may act on the owner through these actions, and nobody may remove themselves — leaving is a separate action on your own membership.

## Invitable roles

Admin, Member, and Billing Manager. Owner is not on the list; the role moves only by transferring ownership to an existing member.

## Notes

- One account belongs to at most one team. Someone already in a team, or owning one, cannot be invited until they leave or dissolve it.
- A role that forces whole-workspace access drags access with it on every role change, in both directions.
- Transferring ownership demotes the previous owner to Admin with whole-workspace access, and moves the subscription to the new owner.
- A permission switch never widens access. Access is only widened by assigning pages, or by a role that forces whole-workspace access.

## Related

- [Work as a team](/guides/teams) — creating a team, inviting, and leaving.
- [Limit a teammate to certain pages](/guides/team-access) — assigning access in the app.
- [Activity log actions](/reference/team-activity-actions) — how each of these changes is recorded.
- [Page permissions and tokens](/reference/page-permissions) — the Facebook-side permissions, which are a separate matter.
