Roles and permissions
Built-in role templates, creating custom roles, and what actually changes when you grant or revoke a permission.
Every member holds exactly one role, and the role defines everything they can do. Roles are managed at Settings → Roles & access (requires the role-management permission — Owner and Admin by default).
How a role works
A role is a set of allowed actions across five categories: CRM Records, Communications, Automation, Reports & Insights, Settings & Team. For record actions (view / edit / delete) each permission also carries a scope — whose records it applies to: Own, Team, Subtree, All, or Projects. Scopes are explained in detail in Who sees which deals.
Granting a permission is not just a hidden flag: the sidebar, the command palette, page guards, buttons, and exports are computed live from the role. Change a role and it applies on the next page load for everyone holding it.
Built-in roles
Ikigai ships role templates you can assign as-is or clone:
| Role | Intended for |
|---|---|
| Owner | Workspace creator. Full control including billing. Exactly one per workspace; cannot be assigned via invite or deleted |
| Admin | Everything except billing: data, settings, team, integrations |
| Manager | Standard sales seat — works own deals, sends messages, no settings |
| Team Lead | Sees and edits the team's deals, can reassign within the team |
| Head of Sales | Their sales subtree (team leads + their teams), edits pipelines, exports reports |
| Sales Director | Same powers with workspace-wide visibility |
| Finance Director | Full CRM visibility with archive rights, full reports and export |
| Accountant | Read-only deals, full reports and export, no customer communications |
| Legal | Reads CRM context, owns the Documents area |
| Customer Support | Owns post-sale projects; sees only project-linked deals and contacts |
Roles marked system (Owner, Admin, Manager) cannot be deleted, but their permissions can still be edited. One permission is locked on system roles — role management: turning it off could leave the workspace without anyone able to edit roles, so the editor refuses.
Creating a custom role
Click New role on the Roles page. You either clone a template ("you can rename and tweak any permission afterwards") or start from the blank Custom role with zero permissions. The editor has three tabs — Access (tick permissions and pick scopes), Review (final preview before save), and Members (who holds the role). Each role gets a name, an optional description, and a badge color.
Changing someone's role
On the Team page open the role cell next to a member and pick Change role. Owner is never assignable this way. You cannot change your own role.
What deleting is gated on
Deleting deals, contacts, and companies is controlled by the delete permission and its scope alone — any role that holds the grant can delete within its scope (the Finance Director template, for example, includes deal deletion by default). One action carries an extra role check: permanently deleting a member is reserved for the Owner and Admin roles regardless of permissions.
Before assigning roles, plan the visibility model: Who sees which deals. To bring people in, see Inviting teammates.
Was this article helpful?