ZyanDocs

Team and permissions

Invite teammates, understand seats and invitation expiry, and use the permission grid — including what full access does and does not grant.

A Zyan workspace has exactly one owner and any number of members. What a member can see is decided entirely by their permission grid: a per-feature matrix of View, Edit, Create and Delete on their own member page. Nothing else grants access, and hiding a menu item is not access control — every page re-checks.

Before you start

Inviting, editing permissions and removing people are owner-only. A member with the Team permission sees the roster read-only. You also need a free seat — pending invitations count against the limit.

The Team page showing member cards with role badges, job titles and per-member counters
Each card carries the member's role and their own numbers. The tabs above split members from pending invitations and from the activity log.

Invitation sent

Role, payroll and the whole permission grid are set on the form

Pending

Holds a seat; the link expires after seven days

Accepted

They set a name and password, or sign into an account they already have

Member page

Allow full access and project assignment appear only now

Everything set on the invite form can be changed afterwards — but full access cannot be granted before someone accepts.

Invite a teammate

Open the invite form

Go to TeamInvite team member. The button is disabled with an explanation when the seat limit is reached.

Enter the email address

Required. Display name is optional and only pre-fills their name.

Pick a Role

Operations, Sales Rep or Developer. The role seeds a default permission and payroll shape — sales reps get commissions and the sales tools, developers get projects, tasks and Builder.

Pick a Job role and Compensation model

Job role is roster metadata, with one exception: choosing Bookkeeper applies a preset of Bookkeeping (view, edit, create) and Billing (view).

Set Include in payroll

Whether they appear on owner payroll and can see My Pay. It follows the role you chose unless you change it.

Tick the permission rows they need

Or click Select all to grant every row at once.

Click Send invitation

What the invitation is

An invitation is a one-time link of the form https://<your workspace address>/accept-invite?token=…, always on your own workspace address. It expires seven days after it is created.

Your teammate opens it, confirms the invited email, enters a full name and a password of at least eight characters — or signs into an account they already have, or continues with Google — and clicks Accept Invitation.

Allow full access is not on the invite form

The Allow full access switch only appears on a member's page after they have accepted. You cannot invite somebody straight to admin.

Seats

The seat banner at the top of Team reads "N of M seats used". It is hidden entirely on unlimited plans.

  • Pending invitations consume seats. Revoking one under TeamInvitations frees it immediately.
  • Builder seats are a separate cap with their own count, and the workspace owner is exempt from it.
  • When every seat is taken, Invite team member is disabled rather than failing after you fill the form in.

The Team page

TabWhat it holdsWho sees it
MembersSearchable roster with role, access summary and 7-day activityAnyone with the Team permission
InvitationsPending invites, with resend and revokeOwner
ActivityWorkspace-wide audit feedOwner
QuicklinksDrag-to-reorder shortcut buttons shown on dashboards across your portalsOwner

A quicklink needs button text and a destination — either an internal path such as /admin/sales-dashboard?tab=pipeline or a full URL. Leaving the list empty hides quicklinks for everyone.

The member workspace

Open TeamMembers and click a teammate. Their page has nine tabs: Overview, Profile, Permissions, Access, Check-ins, Time, Pay, Audit and Files.

  • Profile — display name, team role, job role, compensation model and payroll inclusion. Switching Team Role to Sales Rep unlocks commissions and Stripe Connect onboarding. The access-level badge here is read-only; it is changed on Permissions.
  • Permissions — the grid, the quick actions, Allow full access, Message anyone, and the Builder action permissions.
  • Access — which projects and clients they are assigned to, each as Viewer, Contributor or Manager, plus the Allow all access switch.
  • Check-ins, Time, Pay, Audit, Files — their standups, clocked hours, pay statements, audit trail and uploads.

The account-actions menu on the page holds Suspend Access, Reactivate and Delete.

The permission grid

Each row is one feature. Each row has four columns.

ColumnMeans
ViewSee the area and read its data
EditChange existing records
CreateAdd new records
DeleteRemove records

Two rules govern the grid, and they are not optional:

  • Ticking Edit, Create or Delete automatically ticks View. You cannot grant write access without read access.
  • Unticking View clears the whole row. Removing read access removes everything with it.

Three quick actions sit above the grid: Grant All View, Grant All Edit and Revoke All. They apply across every grantable row at once.

A never-configured member is denied everything

A member whose grid has never been saved shows an amber notice saying so. Everything stays denied until you press Save at least once — even rows that look ticked.

Allow full access

Allow full access makes a teammate owner-equivalent for features, team permissions, billing and audit. While it is on, the grid above is kept but ignored, and the quick-action buttons are disabled.

It does not grant:

  • the workspace subscription — Settings → Plan & Credits stays visible to the workspace owner account only, and no admin can change the plan;
  • the owner account itself;
  • arming autonomous sending.

You also cannot turn it on for yourself, for the workspace owner, or for somebody who has not accepted their invitation yet.

Two toggles beside the grid

  • Message anyone lets a teammate start team conversations with anyone in the workspace rather than only the owner and teammates on shared projects. Recipients can always read and reply.
  • Builder Action Permissions gate what they can do inside Builder: Terminal, Git Push, Create Branches, Open PRs, Protected Push, Deploy, Manage Env, Manage Backup, Components and SEO Local Runs.

Project and client access

The Access tab assigns individual projects and clients. Allow all access assigns every project as Manager and every client as Viewer, and keeps including new ones as they are created.

Turning Allow all access off clears assignments

It does not revert to what was there before. Every project assignment and every manual client grant is cleared, and you rebuild them by hand.

Feature-key reference

Each row in the grid has an internal feature key. Error messages quote it, so it is worth being able to read one.

KeyLabelWhat it covers
calendarCalendarView and manage tasks, meetings and schedule
notesNotesThe internal vault and documentation
projectsProjectsView, edit or delete assigned project workspaces
tasksTasksTask assignments and progress tracking
requestsRequestsClient revision requests
approvalsApprovalsApproval workflows and sign-offs
messagesMessages PageAccess to the Messages area. Individual tabs are controlled by the rows below
messages_clientClient MessagesClient portal conversations
messages_teamTeam MessagesInternal team conversations
messages_smsText MessagesThe text inbox and replies
messages_channelsConnected channelsSlack channels and Telegram chats in Messages. Edit allows replies
leadsLeadsThe lead pipeline and follow-ups
sales_dashboardSales DashboardKPIs and shortcuts for sales reps
sales_activitySales ActivityTimeline of lead and pipeline actions
sales_pipelineSales PipelineDeals, stages and upsells
clientsClientsClient records and details
portalsClient PortalsPortal access, onboarding, settings and delivery
billingBillingClient subscriptions, invoices and the billing catalog
commissionsCommissionsSales rep pay statements and receipts
payrollPayrollStatements, hours import, adjustments, payouts and pay-statement PDFs. View reads, Edit manages
timesheetsTimesheetsShift scheduling, clocked-hours review, punch audit and day corrections. Deliberately separate from Payroll so scheduling can be delegated without handing over pay
filesFilesThe internal team file workspace. Create uploads, Edit shares and renames, Delete removes own items
bookkeepingBookkeepingOwn-books income and expense tracking, and QuickBooks data
marketingMarketingCampaigns, templates and email lists
announcementsAnnouncementsComposing, scheduling and sending portal, SMS and email broadcasts
automationsAutomationsBuilding and managing workflow automations. Live sends still need an owner or admin
voiceVoice AgentsAgents, campaigns, calls and voice settings. Edit manages, Delete archives
prospectingProspectingThe prospecting workspace. Spends workspace credits
builderBuilderThe website builder. Create allows new Builder projects; Delete allows file-tree deletion only
agent_hubAgent HubAgent workspaces, runs and operator handoffs
zyan_aiZyan AIThe chat workspace and the right-dock assistant. Turns spend workspace AI credits
meetingsMeetingsView shows scheduled team meetings; Create schedules new ones
notificationsNotificationsNotification preferences
teamTeamRead-only roster visibility. Profile edits, grants and removals stay owner-only
settingsSettingsAdmin portal settings

Content Center rows

KeyLabel
content_centerContent Center Base
content_center_publishContent Publish Base
content_center_outreachContent Outreach Base
content_center_command_centerCommand Center
content_center_composerComposer
content_center_contentContent
content_center_inboxDM Inbox
content_center_emailEmail
content_center_outreach_tabOutreach
content_center_reviewReview
content_center_accountsAccounts
content_center_operatorsOperators

Content Center tabs are an allowlist

Enabling any Content Center tab row turns it into an allowlist: those become the only Content Center tabs that teammate sees. Grant one and you have implicitly denied the rest.

Rows that are not in the grid

Not grantable hereWhere it lives instead
Instagram DMs, Facebook & Messenger, WhatsAppSettings → Messaging → Team access, per member. These are opt-out — absent means visible
Message AnyoneThe dedicated Message anyone switch on the Permissions tab
Ad campaignsEvery ad surface is owner-only, so a grant would change nothing
Messages OverviewNever read — the All Inboxes view aggregates whichever message tabs are granted

Troubleshooting

SymptomCauseFix
Invite team member is disabledEvery plan seat is taken, pending invitations includedRevoke a pending invite under Team → Invitations, remove a member, or upgrade the plan
“A pending invitation already exists for that address”That email was invited already and has not acceptedGo to Team → Invitations and resend or revoke the existing one
The invitation link says it has expiredInvitations expire seven days after they are createdRevoke it and send a fresh invitation
The invitee lands on “Sign In to Accept”An account already exists on that emailThey sign in with their existing password to accept
The invitee is refused and offered “Sign out and use another account”They are signed in as a different accountSign out, then reopen the invitation link
No Continue with Google button on the invite pageGoogle sign-in is not offered inside the desktop or iOS admin shellsAccept the invitation in a browser
A teammate's grid looks right but they still see nothingThe plan does not sell the feature, Allow full access is on and the grid is ignored, or the grid was never savedCheck Settings → Plan & Credits, check the full-access switch, and press Save on the grid at least once
A teammate still sees Instagram, Facebook or WhatsApp conversationsThose three rows are not in the permission grid and are opt-outTurn them off under Settings → Messaging → Team access
Access seems to survive a suspension or a revokeTheir sign-in token still carries the old workspace roleHave them sign out and back in, then confirm
The Allow full access switch is disabledYou cannot use it on yourself, on the workspace owner, or on somebody who has not accepted yetWait for acceptance, or ask the owner