Access is layered, and the layers compose. A person's rights are the sum of the Workspace role, the Spaces and teams they belong to, and the Campaign roles they hold.
Workspace roles
- Owner. Full control, including billing and deleting the Workspace.
- Admin. Manages members, Spaces, teams and settings.
- Member. Sees what their Space and team membership gives them.
Invite people from the members screen, pick the role, and change it later from the same place. Ownership is the only role that carries billing rights, so keep it with someone who should see invoices.
Space and team roles
A Space has Space Admins, Contributors and Viewers. A team has Admins, Editors and Viewers. Teams are granted access to specific Brands, and sub teams inherit that access unless you override it on the sub team.
This is where most access questions are answered in a larger organization. If someone cannot see a Brand, check the team that grants it before you change their Workspace role.
Campaign roles
People and Agents are assigned to a Campaign in a named role: Campaign Manager, Social Media Manager, Content Writer, Graphic Designer, Motion Artist, Analyst, Advertiser.
The role decides which Content Slots are routed to them and which stage of an Approval Workflow they can act on. Someone in a non manager role gets a contributor dashboard showing only the slots assigned to them.
Campaign roles also matter commercially. Your plan meters how many of each AI role you get, and the same role can be filled by a person or by an Agent. See Billing and plans for what each plan includes, and /pricing for the current figures.
Approvals and roles
An Approval Workflow stage names the role that must act on it. Auto approve rules can let a named role skip a stage. Because stages are defined by role rather than by person, a change of staff does not break the chain. See Approvals.
Agents and permissions
An Agent acts under the tools you allow it and the governance rules of the Workspace. Agent configuration itself is governed by role, so you can decide which Workspace roles may edit which parts of an Agent, such as the system prompt, the tool list or the spending cap. See The AI workforce.
Collabre staff access
Collabre support cannot enter your Workspace unless an Owner grants access. Support access is time boxed, read only, and recorded. When a member of our staff is acting inside your Workspace, a banner says so for the whole session, and every action is written to the audit log. See Security controls and the security page.
Auditing who did what
Two records answer the question. Per entity change history shows what changed on a record, with the values before and after. The Workspace audit log is searchable across everything, including Agent actions and their stated reasoning, and it is the record to export when someone asks for evidence.