Roles and permissions for your team

Getting startedUpdated October 7, 2026

How the owner, admin, and member roles work, and how to build custom roles that grant exactly the access a team member needs.


On this page

Every person on your workspace team holds a role that controls what they can see and do. OrganizeOS ships three built-in roles and lets you build custom roles in between them for anything more specific. Manage roles from Settings, then Access, then Roles.

The built-in roles

  • Owner has full access to everything, including billing and the ability to delete the organization. Every organization has exactly one owner. To hand the organization to someone else, the owner uses Transfer ownership in the Danger Zone of Settings: the new owner must already be on your team, and the previous owner stays on as an admin. The owner cannot leave the organization until they have transferred it.
  • Admin manages members, content, and most settings, but not billing.
  • Member has basic access: they can sign up for actions and see their assignments, but no admin powers. On the Team roster this shows as Team member: someone on your team with no custom role has basic workspace access and nothing more.

Owner and admin sit above everything else and can never be handed out through a custom role. Only the owner can make someone an admin, whether by inviting them, promoting them, restoring a removed admin, or accepting an applicant whose position defaults to admin; the owner role itself moves only through Transfer ownership. The same goes for billing and the danger zone (including deleting the organization): they stay with owners, so a custom role cannot include them and the role editor does not offer them.

Custom roles

Between admin and member, you can define custom roles that grant a specific set of permissions instead of an all-or-nothing choice. A permission is a single capability, like viewing contacts, managing email campaigns, or sending SMS to your own assigned contacts, and permissions are grouped by area: people and CRM, outreach, events, actions, fundraising, members, community, volunteers, analytics, and settings.

To create one, go to Roles and select New custom role. Give it a name, then check off the permissions it should carry. You can start from a template to save time:

TemplateWhat it's meant for
OrganizerManages events, outreach campaigns, and basic CRM
FundraiserManages donations, fundraising campaigns, and donor analytics
Content ManagerManages email content and public pages
Read OnlyCan view everything but cannot make changes

Pick a template as a starting point and adjust individual permissions from there, or build a role from scratch.

Some pages stay with owners and admins whatever custom role someone holds, including your organization's settings and brand, and the Website tool's Profile, Style, Settings, and Shop settings.

A new organization can also start with custom roles already defined. The creation flow's Structure step proposes roles that fit the kind of organization you chose (an Organizer and a Steward for a union local, a Field Organizer and a Finance Director for a campaign headquarters), each tagged with a worker role so it groups correctly here. Switch off the ones you do not need or rename them before creating; fine-tune their permissions afterwards from this page. See Creating your organization.

An existing organization can add a template's roles too. Select Apply a template on the Roles page, pick a template, and keep or untick each role it proposes. Roles you already have are shown as Already exists and are never duplicated. Tick Also add this template's departments to create its departments at the same time, each already set up with the roles its admins can assign (see Departments). Only owners and admins can apply a template.

Event and volunteer permissions

The event and volunteer permissions do what they say for any custom role that holds them, in the workspace and in the mobile app. A role without a permission cannot do that thing, however it was built.

PermissionWhat it lets someone do
Create new eventsStart an event from Events, then New event, including recurring events. They can see the drafts they create.
Edit any event in the organizationEdit and publish any event, drafts included.
Edit only events you createdEdit the events they created themselves, and publish them with the editor or the Publish button. It stops applying to a person who leaves the team or whose role loses the permission, so a former organizer cannot keep changing their events.
Delete eventsDelete an event with its Delete button. Also shows draft events on the Events page, with the Status filter.
Manage RSVPs for eventsOpen an event's RSVPs tab to see its registrations and export them as a CSV, send announcements from its Broadcast tab, turn off or reword its automated messages on the Communications tab, read its Feedback tab, and open Registrations from the Events list. They can also see the organization's draft events.
Check attendees in at eventsUse the Check-in tab or the check-in buttons on the RSVPs tab to mark people as arrived, and undo it. The mobile app's door check-in follows the same permission. They can also see the organization's published private events so they can check people in at them, but not its drafts.
View volunteer activity and shiftsOpen Recruitment and read posts, drafts and closed ones included, and their applications.
Create and edit volunteer shiftsOpen Recruitment, create, edit, publish, pause, and close recruitment posts, and mark an application Reviewing or Reject it.

A few things to know when you build a role from these:

  • Creating is not editing. A role with only Create new events can start an event but cannot change it afterward. To let someone create events and keep working on their own, give the role both Create new events and Edit only events you created; the Create & Edit Own preset does exactly that, and also adds Check attendees in at events.
  • Accepting an applicant stays with owners and admins, because it adds a person to your team. A role that reviews applications can mark them Reviewing or reject them, and an owner or admin does the accepting.
  • Some event tabs stay with owners and admins whatever a custom role holds: Shifts, Questions, Series, and Outcomes. The tabs a custom role can open are Overview, Edit, RSVPs, Check-in, Broadcast, Communications, and Feedback, each under the permission in the table. A tab the person cannot open is not shown to them. The Check-in tab also opens for Manage RSVPs for events, but only Check attendees in at events lets someone record an arrival.

Canvassing permissions

Assign walk lists to canvassers also lets the holder access the notes, GPS location and photos of every door attempt in your organization, whoever recorded it, though no screen shows them yet. Give it to field managers only. View canvassing dashboards and territories opens the Canvassing dashboard and Live Tracking for people on your workspace team, with totals and counts but no door-level detail. A volunteer always sees their own attempts, and a team lead can access the attempts on their team's walk lists. A door's result and mapped survey answers also reach the contact's record; see Who can see door-level data. See Canvassing and Canvassing teams.

Contact permissions

Your contacts are visible to the people who can open the staff workspace: owners, admins, anyone with a custom role, and anyone whose position is Staff, Employee or Organizer. Members and volunteers do not see your contacts, with one exception: a volunteer canvassing a walk list that is assigned to them sees the names on that list's doors, and only while it is assigned to them.

Seeing contacts and changing them are separate. Each change needs its own permission, in the workspace and in the mobile app, and a button for a change someone cannot make is not shown to them.

PermissionWhat it lets someone do
View every contact, not just assigned onesOpen the CRM's contact list, contact records, pipeline and tasks.
Create new contactsAdd a contact with Add Contact on the CRM contact list, or from the mobile app's People screen.
Edit any contact in the CRMChange a contact's details, stage and tags; add notes, tasks, logged calls and meetings, relationships and custom-field values; use the bulk status, stage and tag changes; and review duplicates.
Delete contactsDelete contacts, restore them from Recently deleted within 30 days or remove them for good, and delete anyone's notes.
Create and manage contact tagsCreate, rename and delete tags on the Tags page.
Create new CRM segmentsCreate and change segments, and add or remove contacts in a static segment.

Someone assigned a task can still mark it done without Edit any contact in the CRM. Logging a one-on-one needs the one-on-one permissions, not the contact ones.

When contacts became staff-only in October 2026, members whose position was Staff, Employee or Organizer and who had no custom role were moved to a new Staff (contacts) role, so they kept seeing the contact list. Like any role, it uses a team seat. If your organization was at its team seat limit, they stayed members instead; give them a role from People, then Team when you have a seat.

Campaign race permissions

Campaign workspaces have two permissions under Campaign race: See the campaign's race, key dates and vote goal, and Set up and change the race, its elections, deadlines and vote goal. Owners and admins hold both, and members hold neither. A custom role holding the second can manage your campaign's elections from Campaign Advisor, then Elections; see FEC compliance settings. The Campaign headquarters and Issue or ballot campaign templates give their Field Organizer, Finance Director, Communications Director and Coalition Lead roles the first.

Who sees members' phone numbers

People on your workspace team see a member's phone number where their role gives them a reason to:

  • View the member directory shows it on People, then Members and People, then Team, on a member's page, and in the mobile app's roster and member details.
  • Export the member list includes it in the People export.
  • Manage RSVPs for events shows it for each signed-in attendee on an event's RSVPs tab and in its CSV.
  • On a contact's record, composing a message falls back to the phone number on the contact's linked account when the contact has none of its own and the account belongs to a member of your organization; the CRM export includes that member's phone and address the same way.

A member's city and state stay visible where your organization shows them, such as its Leadership page.

Roles that manage people

A role that can invite people, change roles, remove people, or manage departments is a people-managing role. Only the owner can create one, change one, or give one to someone (by changing their role, inviting them, making it a position's default, or through a department). Admins can build and hand out every other kind of role. In the role editor those permissions are locked for admins, and a people-managing role opens read-only for them; in the role pickers it is marked (owner only). Admins can still take such a role away from someone or remove them from the team.

Someone whose role lets them change roles or remove people can do that for members and for people whose role gives no more access than their own. They cannot change or remove an admin or the owner, give anyone a role with access they do not have themselves, or change their own role.

Assigning roles

You set a person's role when you invite them (People, then Team, then Invite: choose their Position, then their Role; the role suggested for that position comes from your defaults, and you can pick another; only the owner sees Admin there, and someone whose own custom role lets them invite can only invite into roles that give no more access than theirs), and change it later from their row on People, then Team (or People, then Members): open the row menu and choose Change role. The dialog lists Team member (basic access; Member on the Members roster) and each of your custom roles, described by the areas each unlocks (Website, Shop, CRM, and so on). Pick one and save.

Admin is separate. Owners see Make admin and Remove admin in the same row menu. An admin already has every staff tool except billing and the danger zone, so a custom role is set aside while someone is an admin; removing admin takes them back to basic access, and Change role can then hand them a custom role. Only the owner can make someone an admin or change an admin's role, and nobody can change their own role. Admins can still remove another admin from the team.

A person's position (Staff, Employee, Contractor, Volunteer, and so on) is a different thing: it says what kind of person they are to your organization and is set when you invite them or on their profile page. Who can open the staff workspace follows one rule: owners, admins, anyone who holds a custom role, and anyone whose position is Staff, Employee or Organizer. Everyone else opens the Member space. So a volunteer with a custom role can use the tools that role unlocks, and a staff member with no custom role can open the workspace but only sees the basics; give them a custom role to unlock more. The Team roster lists exactly the people who can open the workspace, and the invite form tells you where a new person will land before you send it.

What the person you invite sees

The invitation email names your organization and the role you chose. When they open its button, they sign in, or create an account if they are new, using the address you invited, and they join right away: there is no second button to press. They land in the staff workspace or the Member space by the rule above.

An invitation link works only for the address it was sent to. Anyone else who opens it, including a teammate who copied it from People, then Invites, is asked to sign in as the invited address first. If an invitation has expired, choose Resend on its row in People, then Invites to send a fresh email with the same link.

If you want to hand a subset of your team the ability to assign roles themselves, without giving them full admin, see Departments and delegated admin — departments let you cap exactly which roles a delegated admin can hand out.

Why this matters

Handing out "admin" by default because it's the easy button is how workspaces end up with more people than intended who can see donor data, change settings, or remove team members. Custom roles let you match access to the job: a canvassing lead gets canvassing and CRM permissions without touching billing; a comms volunteer gets email tools without member management. Permission checks happen on the server every time, so hiding a button in the interface is a convenience for people without access, not the actual security boundary — you can trust that a role's limits hold even if someone pokes around outside the normal UI.