I

Roles and permissions

Built-in role templates, creating custom roles, and what actually changes when you grant or revoke a permission.


Every member holds exactly one role, and the role defines everything they can do. Roles are managed at Settings → Roles & access (requires the role-management permission — Owner and Admin by default).

How a role works

A role is a set of allowed actions across five categories: CRM Records, Communications, Automation, Reports & Insights, Settings & Team. For record actions (view / edit / delete) each permission also carries a scope — whose records it applies to: Own, Team, Subtree, All, or Projects. Scopes are explained in detail in Who sees which deals.

Granting a permission is not just a hidden flag: the sidebar, the command palette, page guards, buttons, and exports are computed live from the role. Change a role and it applies on the next page load for everyone holding it.

Built-in roles

Ikigai ships role templates you can assign as-is or clone:

RoleIntended for
OwnerWorkspace creator. Full control including billing. Exactly one per workspace; cannot be assigned via invite or deleted
AdminEverything except billing: data, settings, team, integrations
ManagerStandard sales seat — works own deals, sends messages, no settings
Team LeadSees and edits the team's deals, can reassign within the team
Head of SalesTheir sales subtree (team leads + their teams), edits pipelines, exports reports
Sales DirectorSame powers with workspace-wide visibility
Finance DirectorFull CRM visibility with archive rights, full reports and export
AccountantRead-only deals, full reports and export, no customer communications
LegalReads CRM context, owns the Documents area
Customer SupportOwns post-sale projects; sees only project-linked deals and contacts

Roles marked system (Owner, Admin, Manager) cannot be deleted, but their permissions can still be edited. One permission is locked on system roles — role management: turning it off could leave the workspace without anyone able to edit roles, so the editor refuses.

Creating a custom role

Click New role on the Roles page. You either clone a template ("you can rename and tweak any permission afterwards") or start from the blank Custom role with zero permissions. The editor has three tabs — Access (tick permissions and pick scopes), Review (final preview before save), and Members (who holds the role). Each role gets a name, an optional description, and a badge color.

Changing someone's role

On the Team page open the role cell next to a member and pick Change role. Owner is never assignable this way. You cannot change your own role.

What deleting is gated on

Deleting deals, contacts, and companies is controlled by the delete permission and its scope alone — any role that holds the grant can delete within its scope (the Finance Director template, for example, includes deal deletion by default). One action carries an extra role check: permanently deleting a member is reserved for the Owner and Admin roles regardless of permissions.

Before assigning roles, plan the visibility model: Who sees which deals. To bring people in, see Inviting teammates.

Was this article helpful?

Related articles

Roles and permissions · Help Center