Team permissions done right: balancing access and security

Collabre ·

Every growing team meets the same problem. Open the Workspace wide, and somebody publishes a draft by accident. Lock it down, and the work queues behind whoever holds the keys. Neither setting is a policy. A policy is a set of layers, each answering a narrower question than the one above it.

Access is layered, and the layers compose

Collabre splits access into levels that stack rather than compete.

The Workspace level decides who runs the account. An Owner controls billing and can delete the Workspace. An Admin manages members, spaces, teams and settings. A Member gets what their space and team membership grants, and nothing beyond it.

Spaces and teams narrow that further. A space has Space Admins, Contributors and Viewers. A team has Admins, Editors and Viewers. Teams are granted access to specific Brands, and sub-teams inherit that access unless it is overridden for them.

The Campaign level is where the daily work sits. People are assigned to a Campaign in a named role: Campaign Manager, Social Media Manager, Content Writer, Graphic Designer, Motion Artist, Analyst or Advertiser. The role governs what that person does on that Campaign. It does not follow them to the next one.

That last point does most of the useful work. A writer who joins one client for one project is a Content Writer on that Campaign only. You do not have to invent a new job title, and you do not have to hand out Workspace access to solve a Campaign problem.

Publishing rights belong to the review chain

The permission that people worry about is publishing. Treat it as a review question rather than an account question.

An Approval Workflow is an ordered chain of stages. Each stage names the role that has to sign off and a deadline in hours. Workflows are set per Brand, or as a Workspace-wide default, so the demanding client can carry a longer chain than the easy one. Auto-approve rules cover the roles you trust to skip a step. Pending approvals that pass their deadline escalate on their own, which is the part an email thread never does.

Posts run through that chain, Content Slots inside a Campaign carry their own review layer on top, and a media asset is reviewed the same way. So a junior can draft freely, and the question of whether the draft ships is answered by the workflow rather than by a setting on their account.

Read how the chain is built on the campaigns and approvals page.

Give the client a role, not a password

Clients need to see what is coming and say yes to it. They do not need the inside of your production board.

Put the client in the Approval Workflow as a review stage with a deadline. They see what is waiting for them, and the clock is visible to both sides. For visibility without an account, the content calendar generates a read-only link with an optional expiry date. The link renders the calendar and nothing else.

Agents follow the same rules, and a few more

An Agent is assigned to the same Campaign roles a person can hold, so the layers above apply to it unchanged. The extra controls sit on top.

The Autopilot level is set per Campaign and starts at Suggest Only, so an Agent proposes and a person decides. Tool approval rules default to human confirmation on every call, and a tool can be denied outright at Workspace, Agent, Department or Campaign scope. Spending caps apply per run, per Agent per day, and per Workspace per month. Kill switches stop one Agent or every Agent at once. Personal data is redacted from logs and Agent inputs by default.

The log is the part you will be glad you kept

Two logs matter when somebody asks what happened.

Per-entity change history records the before and after values on a single record. The Workspace-wide audit log is searchable across everything, including every Agent action and the reasoning behind it. A separate login activity log shows the method, the location and the failures.

Two-factor authentication with backup codes covers the accounts themselves. API keys carry scopes and rate limits, so an internal script reads only what it needs. Support access from Collabre is time-boxed, granted by an Owner, read-only, and recorded.

Where to start

Start with the review chain, not the permission matrix. Write down who has to approve work for each Brand and how long they get. Turn that into an Approval Workflow. Then assign people to Campaigns in the role they actually play, and leave Workspace admin to the people who handle billing and settings.

The result is a team that can add a freelancer on Monday without a meeting about access, and an account you can still explain to a client's security reviewer. See the controls in one place on the security page.