Owner
Full access: billing, API tokens, webhooks, integrations, clearing the activity log, and deleting the account (which also deletes workspaces where they are the only owner). Owners can assign any role, including Owner and Admin.
Admin
Create, edit, and delete clients and assets; manage team, settings, CSV import/export, and reminder rules. Cannot open billing, API keys, or integrations. Admins can assign Member or Viewer only.
Member
Create and edit clients and assets. Cannot delete records, manage settings, invite people, or export/import CSV.
Viewer
Read-only access to workspace data. Cannot complete onboarding actions that write data.
Assets are not assigned to individual users. Owner/payer on an asset means agency, client, or unknown — not a teammate.