Skip to content

What can each Account role do?

An Account role sets the person's level of access within that Account. The roles are Owner, Admin, Member, and Guest. Product permissions can further control access to individual resources.

RoleAccount access
OwnerManages the Account, invitations, app access, billing, and domains.
AdminManages permitted directory and group resources.
MemberUses available products and participates in groups they can access.
GuestHas limited access to the Account.

In Admin, only owners can manage invitations and billing, change the Account image, name, or handle, or delete the Account. Owners also create and verify domains. Other roles may see read-only information where their permissions allow it.

An Account owner or admin, and the owner of a group, can manage that group's members. The group owner must remain a member of the group.

Change someone's role

An Account owner can open Directory → People in Admin, select a person, and choose Edit. Change Role, then save. A change that grants or removes ownership requires an additional confirmation.

You cannot change your own Account role. Ask another owner to make that change. We refuse to reduce the last owner's role, but the check can count an inactive owner. Before reducing an owner's role, confirm that another owner is active and can sign in.

If you change a person from Guest to another role in an Account with Workspace billing, the Account first uses an unoccupied paid human seat. If none is available, the change requires payment for the rest of the billing cycle and adds matching usage credit. Payment failure can prevent the role change. After saving, reopen the person's profile and confirm the saved role.

If an owner-only page is missing from navigation, check your role in the selected Account. Opening its URL does not bypass the role check; Admin returns you to Home when the destination is unavailable to your role.