How team roles and permissions work
BrandOps controls access with four roles (Owner, Admin, Member, Viewer) applied in two separate places: organization-wide admins who see every brand, and brand-level team members scoped to one. Getting that split right is the key to inviting the right person to the right thing.
This guide walks through the role hierarchy, where each is managed, and what each level can and can't do.
The role hierarchy
Every person in BrandOps holds exactly one of four roles, ranked in this order everywhere the app sorts a team list: Owner, Admin, Member, Viewer.
- Owner: the top role. Full control of the workspace including billing. There's exactly one, and their row never shows a Remove option.
- Admin: can manage team members, send invites, and edit workspace or brand settings, but doesn't carry the irrevocable status an Owner has.
- Member: full access to create and edit data (tasks, content, clients, whatever your business type exposes) but can't touch team membership.
- Viewer: read-only. Can look at everything but can't create or change anything, and the app tells them so directly on the Team tab.
- These same four roles and the same ranking apply whether you're looking at organization-wide admins or a single brand's team.
Organization Admins vs Brand Team
BrandOps splits team management into two separate places on purpose, because access to "everything" and access to "one brand" are genuinely different grants.
- Organization → Team (at /dashboard/organization?tab=team) lists your org-wide admins: every member with the Owner or Admin role. Its subheading says exactly what they get: full access to every brand in your workspace, plus billing.
- Settings → Team (at /dashboard/settings?tab=team) is scoped to whichever brand you currently have selected. It lists that brand's own team plus, read-only, any org Owner or Admin, labelled with an "Org" prefix on their role badge, since they already have implicit access without needing a separate grant.
- A brand invite only ever offers Admin, Member, or Viewer for that one brand. There's no way to invite someone as a brand-level Owner; Owner is an organization-wide role.
- If you're running a single brand, this distinction barely matters day to day. It matters a lot once you're on Agency and running multiple brands from one organization; see the Multi-Brand guide.
Inviting people
Invites work the same way in both places: pick an email, pick a role, send it. Only Owners and Admins see the Invite button.
- An org invite (sent from Organization → Team) offers Admin, Member, or Viewer, and grants access across the whole workspace.
- A brand invite (sent from Settings → Team) offers the same three roles but grants access to that one brand only.
- Pending invites show up in their own list with who sent them and when, so you can see what's outstanding before someone accepts.
- An Owner or Admin can revoke any pending invite before it's accepted, right from that same list.
- You can change someone's role later; it isn't locked in at invite time.
Removing access
Removing someone is a per-row action on the team list, gated the same way invites are.
- Only Owners and Admins can remove people, and a confirmation step (Remove / Cancel) appears before it's final.
- You can never remove the Owner, and you can never remove yourself from a team list. Both are blocked outright.
- Removing someone from a brand's team only revokes that brand's access. If they're also an org Owner or Admin, they'll still show up as an implied admin, because that access comes from the organization, not the brand.
- Removal is immediate. There's no offboarding delay or grace period.
Frequently Asked Questions
What's the difference between an Organization Admin and a Brand Team member?
An Organization Admin (Owner or Admin role, managed at Organization → Team) gets automatic access to every brand in your workspace, plus billing. A Brand Team member (managed at Settings → Team) is only granted access to one specific brand. Org Owners and Admins show up in a brand's Team tab as read-only 'implied admins' since their access comes from the org, not a per-brand grant.
What are the four roles and what can each one do?
Owner has full control including billing and can't be removed. Admin can manage team members, invite people, and edit workspace or brand settings. Member has full access to create and edit data but can't manage the team. Viewer has read-only access and can't create or change anything.
Can I remove the workspace Owner?
No. The Remove option never appears next to the Owner's row, and you can't remove yourself either. Ownership has to be reassigned by contacting support.
How do I invite someone to just one brand instead of the whole organization?
Go to Settings → Team (not Organization → Team) and click Invite. That sends a brand-scoped invite with a role of Admin, Member, or Viewer for that brand only. They won't get access to your other brands or to billing.
Who can invite new people?
Only Owners and Admins see the Invite button, on both the org Team tab and a brand's Team tab. Members and Viewers can see who has access but can't invite, remove, or change roles.
Can I cancel a pending invite?
Yes. Pending invites appear in their own section with when they were sent and who sent them. Owners and Admins can revoke any pending invite before it's accepted.
What happens if I'm on the Viewer role?
You can see the team list but the page tells you directly: you have viewer access, and you'll need to ask an admin or the workspace owner to manage team membership on your behalf.
Ready to bring your team in?
Open Organization → Team to invite an org-wide admin, or a brand's Settings → Team to add someone to just that brand.
Go to Organization AdminsRelated guides
Organization vs Brand Settings guide
See exactly what lives at the organization level versus the brand level, and why BrandOps splits them.
Multi-Brand Workspaces guide
Run multiple brands or client accounts from one organization on the Agency plan.
AI assistant guide
Use the AI assistant for daily briefings, urgent issue detection, and workflow improvement tips.
Something unclear? Contact support or send feedback from your dashboard settings.
