Skip to content

Roles & permissions

A workspace has four roles. They control everything from publishing a product to changing the plan. This page is the canonical lookup — every Team and Workspace guide links back here.

Most people should be an Editor

Editors can build the store, ship products, manage customers, and pull income reports. They just can't change plan, change workspace settings, or manage the team. If in doubt, invite people as Editors and promote later.

The four roles

RoleOne-liner
OwnerThe person who created the workspace and pays for the plan. Exactly one per workspace. Ownership is set at workspace creation and is not part of the assignable roles — it cannot be granted through an invite.
AdminFull operational access. Manages settings, custom domain, team, and customers. Can't touch billing.
EditorBuilds the store and products. Can do everything content-related and pull income reports, but can't change settings or manage the team.
ViewerRead-only access to the store page. Gets redirected away from the dashboard. Useful for stakeholders who want to see what's live, not edit it.

Ownership is set when the workspace is created and can't be granted through an invite. Admin, Editor, and Viewer are the three roles you can assign.

Capability matrix

A ✓ means the role can do the action. A ✗ means it's blocked.

Workspace

CapabilityOwnerAdminEditorViewer
View workspace
Switch into workspace
Update workspace name and settings
Manage workspace integrations (e.g. Google Calendar)
Leave workspace (self)

Store & pages

CapabilityOwnerAdminEditorViewer
View the store
Edit store appearance and product pages
Upload store avatar
Manage store settings (slug, publish)
Configure custom domain
View store analytics
Manage checkout flow / offers

Products

CapabilityOwnerAdminEditorViewer
Create products
Update products
Reorder products
Upload product thumbnails
Delete products
Edit courses, lessons, appointments
Update membership bundled products
Manage digital downloads
Upload video media
Create or update events
Delete events

Customers

CapabilityOwnerAdminEditorViewer
View customers
Create / update a customer
Set or reset customer password
Delete a customer
Bulk-delete customers
Suspend / resume an enrolment
Reset a customer's course progress
Resend course access credentials
Cancel or reschedule a customer's booking

Payments & income

CapabilityOwnerAdminEditorViewer
View income report
Create customer subscriptions
Update / pause / resume subscriptions
Cancel subscriptions
View subscription analytics
Refund a payment

Communities

Community-level moderation is separate (see below).

CapabilityOwnerAdminEditorViewer
Create a community
Update community settings
Delete a community
Manage categories / resources / courses
Invite community members
Remove a community member

Team management

CapabilityOwnerAdminEditorViewer
Invite Editors and Viewers
Invite Admins
Change another member's role✓ (Editor/Viewer only)
Change another Admin's role
Remove an Editor or Viewer
Remove another Admin
Resend / cancel pending invitations✓ (Editor/Viewer only)

Billing & plan

CapabilityOwnerAdminEditorViewer
Choose or change the workspace plan
View invoices and update payment method
Cancel the subscription

Plan-tier seat limits live in /for-creators/reference/plans.

Owner-only operations

Only the Owner can do these

These actions are gated to the workspace owner. There is no way to delegate them — not even to an Admin.

  • Choose, change, or cancel the workspace plan. Billing in the platform is owner-keyed.
  • Update payment method and view billing history.
  • Restore custom domain access after a plan lapse. Configuring a custom domain takes Owner or Admin. If the plan lapses, the custom-domain page is locked until the Owner reactivates the plan — Admins can't unlock it themselves.
  • Remove or demote another Admin. Admins can't act on each other.
  • Transfer ownership is not currently supported. Ownership is set at workspace creation and there is no in-app transfer flow. If you need to hand a workspace to a new owner, contact support.

We recommend that Owner accounts use a shared business email under your control, so the workspace isn't tied to a single individual's address.

Edge cases & quirks

Viewer is auto-redirected away from the dashboard

A Viewer who navigates to the Dashboard is redirected to the Store page instead — they don't see income, customers, or product management. If a new team member tells you "I can't find the Dashboard," double-check they were invited as Editor, not Viewer.

Workspace admins inside a community are protected

Workspace Owners and Admins are auto-joined to every community as a community admin. Those memberships can't be demoted or removed from inside the community UI — the only way to take an Admin out of a community is to change their workspace role first.

Pending vs accepted invitations. A team invitation is in "pending" status until the invitee clicks the link and accepts. While pending, they don't have a role yet, but the invitation does count against your plan's team-member ceiling. Invitations expire after 7 days — you can resend or cancel them at any time, and you can always re-invite the same email later without manual cleanup.

Invitation flow

The role-of-inviter rules:

InviterCan invite Admin?Can invite Editor?Can invite Viewer?
Owner
Admin
Editor / Viewer

You can't invite the workspace Owner's email, and you can't invite yourself. If an invitation for the same email already exists and hasn't expired, the request is rejected — cancel the existing one first.

A new team member who accepts an invitation while logged out is taken through signup, then attached to the workspace at the role specified in the invitation. If they already have a Klixey account, the invite-email and the account-email must match exactly.

Workflow guides: /for-creators/team/inviting-members and /for-creators/account/workspace-settings.

When the Owner's plan lapses

If the workspace Owner's subscription ends — whether they cancelled, the card failed, or the trial expired — the workspace is suspended for everyone except the Owner.

What this looks like:

  • The Owner is redirected to the billing page with "Your subscription has ended. Choose a plan to continue."
  • Admins, Editors, and Viewers see a "This workspace is currently inactive" screen. They can't edit anything until the Owner reactivates the plan. They can switch to another workspace if they have one, or leave this one entirely.

Suspension takes effect the next time someone in the workspace opens a page.

Leaving a workspace

Non-owners can leave at any time. Use the workspace menu → Leave workspace. You'll need a new invitation to rejoin.

Owners cannot leave their own workspace. Ownership is non-transferable in the current build, and there is no in-app workspace-delete flow. To step away from a workspace you own, contact support — we'll help you transfer ownership or fully remove the workspace.

If you're the last Admin in a workspace and you leave, the Owner still has full control. Workspaces can never be left without an Owner, by construction — there is always exactly one.

Community roles are different

Don't confuse workspace roles with community roles. Inside a community, members have one of:

  • Member — can read and post, subject to community settings.
  • Moderator — can delete posts, remove members.
  • Admin — full control over the community.

These are per-community, not workspace-wide — somebody can be a Moderator in one community and a regular Member in another. Workspace Owners and Admins additionally get an automatic, protected community-admin membership in every community in the workspace (see the quirk above).

Detailed reference: /for-creators/reference/community-roles (coming soon).

See also

© Klixey