Roles and permissions
Understand the three workspace roles and what each role can do.
Invokeable has three customer roles: Admin, Member, and Viewer. The role shown on the Members page is the same role you choose when inviting someone or changing their access.
Workspace roles
| Role | Access |
|---|---|
| Admin | Manages product connections, agents, journeys, findings, members, notification delivery, and workspace settings |
| Member | Works with journeys, assessments, findings, connected-agent summaries, and supporting evidence available to the workspace |
| Viewer | Reads workspace readiness, connected-agent summaries, and available findings without changing workspace data |
The person who creates a workspace is its primary admin. The primary admin can also manage billing and workspace deletion. Those account controls do not create another selectable role.
Choose a role
Use Admin only for people who need to configure the product or manage other members. Use Member for the people who create and review assessments. Use Viewer for people who only need the readiness summary.
Admins can invite people and change a member between Admin, Member, and Viewer. A member cannot change their own role. Invokeable also prevents removal of the only primary admin so that the workspace does not lose its billing and lifecycle owner.
How access is enforced
The interface hides pages and controls that the current role cannot use. Invokeable checks the member's active workspace role again when an action reaches the backend, so a hidden button is not the security boundary.
Some sensitive evidence and approval decisions require an additional access decision. That decision can narrow a person's access for a specific task, but it cannot give them more access than their Admin, Member, or Viewer role allows.
See Workspace and members and Data and privacy.