Team and permissions
Invite teammates, understand seats and invitation expiry, and use the permission grid — including what full access does and does not grant.
A Zyan workspace has exactly one owner and any number of members. What a member can see is decided entirely by their permission grid: a per-feature matrix of View, Edit, Create and Delete on their own member page. Nothing else grants access, and hiding a menu item is not access control — every page re-checks.
Before you start
Inviting, editing permissions and removing people are owner-only. A member with the Team permission sees the roster read-only. You also need a free seat — pending invitations count against the limit.

Invitation sent
Role, payroll and the whole permission grid are set on the form
Pending
Holds a seat; the link expires after seven days
Accepted
They set a name and password, or sign into an account they already have
Member page
Allow full access and project assignment appear only now
Invite a teammate
Open the invite form
Go to TeamInvite team member. The button is disabled with an explanation when the seat limit is reached.
Enter the email address
Required. Display name is optional and only pre-fills their name.
Pick a Role
Operations, Sales Rep or Developer. The role seeds a default permission and payroll shape — sales reps get commissions and the sales tools, developers get projects, tasks and Builder.
Pick a Job role and Compensation model
Job role is roster metadata, with one exception: choosing Bookkeeper applies a preset of Bookkeeping (view, edit, create) and Billing (view).
Set Include in payroll
Whether they appear on owner payroll and can see My Pay. It follows the role you chose unless you change it.
Tick the permission rows they need
Or click Select all to grant every row at once.
Click Send invitation
What the invitation is
An invitation is a one-time link of the form
https://<your workspace address>/accept-invite?token=…, always on your own
workspace address. It expires seven days after it is created.
Your teammate opens it, confirms the invited email, enters a full name and a password of at least eight characters — or signs into an account they already have, or continues with Google — and clicks Accept Invitation.
Allow full access is not on the invite form
The Allow full access switch only appears on a member's page after they have accepted. You cannot invite somebody straight to admin.
Seats
The seat banner at the top of Team reads "N of M seats used". It is hidden entirely on unlimited plans.
- Pending invitations consume seats. Revoking one under TeamInvitations frees it immediately.
- Builder seats are a separate cap with their own count, and the workspace owner is exempt from it.
- When every seat is taken, Invite team member is disabled rather than failing after you fill the form in.
The Team page
| Tab | What it holds | Who sees it |
|---|---|---|
| Members | Searchable roster with role, access summary and 7-day activity | Anyone with the Team permission |
| Invitations | Pending invites, with resend and revoke | Owner |
| Activity | Workspace-wide audit feed | Owner |
| Quicklinks | Drag-to-reorder shortcut buttons shown on dashboards across your portals | Owner |
A quicklink needs button text and a destination — either an internal path such
as /admin/sales-dashboard?tab=pipeline or a full URL. Leaving the list empty
hides quicklinks for everyone.
The member workspace
Open TeamMembers and click a teammate. Their page has nine tabs: Overview, Profile, Permissions, Access, Check-ins, Time, Pay, Audit and Files.
- Profile — display name, team role, job role, compensation model and payroll inclusion. Switching Team Role to Sales Rep unlocks commissions and Stripe Connect onboarding. The access-level badge here is read-only; it is changed on Permissions.
- Permissions — the grid, the quick actions, Allow full access, Message anyone, and the Builder action permissions.
- Access — which projects and clients they are assigned to, each as Viewer, Contributor or Manager, plus the Allow all access switch.
- Check-ins, Time, Pay, Audit, Files — their standups, clocked hours, pay statements, audit trail and uploads.
The account-actions menu on the page holds Suspend Access, Reactivate and Delete.
The permission grid
Each row is one feature. Each row has four columns.
| Column | Means |
|---|---|
| View | See the area and read its data |
| Edit | Change existing records |
| Create | Add new records |
| Delete | Remove records |
Two rules govern the grid, and they are not optional:
- Ticking Edit, Create or Delete automatically ticks View. You cannot grant write access without read access.
- Unticking View clears the whole row. Removing read access removes everything with it.
Three quick actions sit above the grid: Grant All View, Grant All Edit and Revoke All. They apply across every grantable row at once.
A never-configured member is denied everything
A member whose grid has never been saved shows an amber notice saying so. Everything stays denied until you press Save at least once — even rows that look ticked.
Allow full access
Allow full access makes a teammate owner-equivalent for features, team permissions, billing and audit. While it is on, the grid above is kept but ignored, and the quick-action buttons are disabled.
It does not grant:
- the workspace subscription — Settings → Plan & Credits stays visible to the workspace owner account only, and no admin can change the plan;
- the owner account itself;
- arming autonomous sending.
You also cannot turn it on for yourself, for the workspace owner, or for somebody who has not accepted their invitation yet.
Two toggles beside the grid
- Message anyone lets a teammate start team conversations with anyone in the workspace rather than only the owner and teammates on shared projects. Recipients can always read and reply.
- Builder Action Permissions gate what they can do inside Builder: Terminal, Git Push, Create Branches, Open PRs, Protected Push, Deploy, Manage Env, Manage Backup, Components and SEO Local Runs.
Project and client access
The Access tab assigns individual projects and clients. Allow all access assigns every project as Manager and every client as Viewer, and keeps including new ones as they are created.
Turning Allow all access off clears assignments
It does not revert to what was there before. Every project assignment and every manual client grant is cleared, and you rebuild them by hand.
Feature-key reference
Each row in the grid has an internal feature key. Error messages quote it, so it is worth being able to read one.
| Key | Label | What it covers |
|---|---|---|
calendar | Calendar | View and manage tasks, meetings and schedule |
notes | Notes | The internal vault and documentation |
projects | Projects | View, edit or delete assigned project workspaces |
tasks | Tasks | Task assignments and progress tracking |
requests | Requests | Client revision requests |
approvals | Approvals | Approval workflows and sign-offs |
messages | Messages Page | Access to the Messages area. Individual tabs are controlled by the rows below |
messages_client | Client Messages | Client portal conversations |
messages_team | Team Messages | Internal team conversations |
messages_sms | Text Messages | The text inbox and replies |
messages_channels | Connected channels | Slack channels and Telegram chats in Messages. Edit allows replies |
leads | Leads | The lead pipeline and follow-ups |
sales_dashboard | Sales Dashboard | KPIs and shortcuts for sales reps |
sales_activity | Sales Activity | Timeline of lead and pipeline actions |
sales_pipeline | Sales Pipeline | Deals, stages and upsells |
clients | Clients | Client records and details |
portals | Client Portals | Portal access, onboarding, settings and delivery |
billing | Billing | Client subscriptions, invoices and the billing catalog |
commissions | Commissions | Sales rep pay statements and receipts |
payroll | Payroll | Statements, hours import, adjustments, payouts and pay-statement PDFs. View reads, Edit manages |
timesheets | Timesheets | Shift scheduling, clocked-hours review, punch audit and day corrections. Deliberately separate from Payroll so scheduling can be delegated without handing over pay |
files | Files | The internal team file workspace. Create uploads, Edit shares and renames, Delete removes own items |
bookkeeping | Bookkeeping | Own-books income and expense tracking, and QuickBooks data |
marketing | Marketing | Campaigns, templates and email lists |
announcements | Announcements | Composing, scheduling and sending portal, SMS and email broadcasts |
automations | Automations | Building and managing workflow automations. Live sends still need an owner or admin |
voice | Voice Agents | Agents, campaigns, calls and voice settings. Edit manages, Delete archives |
prospecting | Prospecting | The prospecting workspace. Spends workspace credits |
builder | Builder | The website builder. Create allows new Builder projects; Delete allows file-tree deletion only |
agent_hub | Agent Hub | Agent workspaces, runs and operator handoffs |
zyan_ai | Zyan AI | The chat workspace and the right-dock assistant. Turns spend workspace AI credits |
meetings | Meetings | View shows scheduled team meetings; Create schedules new ones |
notifications | Notifications | Notification preferences |
team | Team | Read-only roster visibility. Profile edits, grants and removals stay owner-only |
settings | Settings | Admin portal settings |
Content Center rows
| Key | Label |
|---|---|
content_center | Content Center Base |
content_center_publish | Content Publish Base |
content_center_outreach | Content Outreach Base |
content_center_command_center | Command Center |
content_center_composer | Composer |
content_center_content | Content |
content_center_inbox | DM Inbox |
content_center_email | |
content_center_outreach_tab | Outreach |
content_center_review | Review |
content_center_accounts | Accounts |
content_center_operators | Operators |
Content Center tabs are an allowlist
Enabling any Content Center tab row turns it into an allowlist: those become the only Content Center tabs that teammate sees. Grant one and you have implicitly denied the rest.
Rows that are not in the grid
| Not grantable here | Where it lives instead |
|---|---|
| Instagram DMs, Facebook & Messenger, WhatsApp | Settings → Messaging → Team access, per member. These are opt-out — absent means visible |
| Message Anyone | The dedicated Message anyone switch on the Permissions tab |
| Ad campaigns | Every ad surface is owner-only, so a grant would change nothing |
| Messages Overview | Never read — the All Inboxes view aggregates whichever message tabs are granted |
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Invite team member is disabled | Every plan seat is taken, pending invitations included | Revoke a pending invite under Team → Invitations, remove a member, or upgrade the plan |
| “A pending invitation already exists for that address” | That email was invited already and has not accepted | Go to Team → Invitations and resend or revoke the existing one |
| The invitation link says it has expired | Invitations expire seven days after they are created | Revoke it and send a fresh invitation |
| The invitee lands on “Sign In to Accept” | An account already exists on that email | They sign in with their existing password to accept |
| The invitee is refused and offered “Sign out and use another account” | They are signed in as a different account | Sign out, then reopen the invitation link |
| No Continue with Google button on the invite page | Google sign-in is not offered inside the desktop or iOS admin shells | Accept the invitation in a browser |
| A teammate's grid looks right but they still see nothing | The plan does not sell the feature, Allow full access is on and the grid is ignored, or the grid was never saved | Check Settings → Plan & Credits, check the full-access switch, and press Save on the grid at least once |
| A teammate still sees Instagram, Facebook or WhatsApp conversations | Those three rows are not in the permission grid and are opt-out | Turn them off under Settings → Messaging → Team access |
| Access seems to survive a suspension or a revoke | Their sign-in token still carries the old workspace role | Have them sign out and back in, then confirm |
| The Allow full access switch is disabled | You cannot use it on yourself, on the workspace owner, or on somebody who has not accepted yet | Wait for acceptance, or ask the owner |