Choose roles and permissions

Use owner, built-in, or custom access safely and understand the section rules that protect company operations.

Humind company access combines an owner, three built-in role presets, and optional custom roles. Permissions are grouped by product section with none, read, or write levels, and write includes read. A teammate's platform account type is separate from their role inside a company.

This guide explains the current matrices and protected actions in practical language. Use it before inviting a teammate, changing a role, creating a custom role, deleting a role, or transferring ownership.

How this fits into Humind

Humind access is scoped to a company and controlled by section permissions. Built-in roles cover common operating models, while custom roles support narrower access. The company owner remains a separate, protected responsibility.

Use least-privilege changes that still let a teammate complete their work. After changing a role or invitation, ask the teammate to refresh and confirm the pages and actions they can access instead of relying only on the administrator view.

Before you start

Access: Team management requires team write access. Supervisors have restricted operator-only team management. Custom roles and ownership actions require broader administration; ownership transfer is owner or Humind platform-admin only.

  • List the person's real responsibilities by Humind section.
  • Separate must-edit, read-only, and no-access needs.
  • Identify whether the person should manage other teammates or ownership.

Step-by-step workflow

  1. Understand built-in roles

    Admin has write access across Inbox, handoff, Contacts, Knowledge, Catalog, Agent configuration, Merchant Assistant, Analytics, Agent report, company settings, team, and billing. Operator has write access to Inbox, handoff, Contacts, and Merchant Assistant, with read access to Knowledge and Catalog.

    Supervisor includes the operator operational access, read access to Knowledge and Catalog, read access to Agent report, and team write restricted to managing operators. Supervisor does not receive the full Analytics area or Agent configuration by default.

  2. Use the owner responsibility correctly

    The owner is unique and receives implicit write access across the company. Ownership is separate from a role and protects company deletion and transfer responsibilities. Other members cannot remove or demote the owner.

    Transfer ownership only to an active company admin after explicit confirmation. The current owner is excluded as a target, and a Humind platform administrator has a controlled recovery exception.

  3. Create a custom role for a real gap

    Open Settings, Company, Teammates, then Roles when the current actor can manage roles. Built-in presets are read-only. Create a custom name and description and assign none, read, or write to the relevant sections.

    Use a custom role when the desired matrix differs materially from Admin, Operator, or Supervisor. Avoid creating several nearly identical roles that teammates cannot distinguish.

  4. Change or remove access safely

    Use the member action to change a teammate's role or remove them when authorized. Supervisors cannot edit roles and may remove only operators. A user cannot ordinarily change their own role through the teammate row.

    Deleting a custom role that is still assigned is blocked unless members and pending invitations are reassigned. Review both active and pending users before choosing the replacement.

  5. Test the effective access

    Ask the affected teammate to refresh the workspace and confirm navigation, read access, edit controls, Inbox handoff actions, and restricted pages. Humind invalidates permissions across services, but the user view remains the most useful acceptance check.

    Document the reason and approver for elevated access. Review custom roles when responsibilities change.

Permissions and important caveats

  • Platform role and company role are separate; company permissions control the B2B sections described here.
  • The owner has protected responsibilities that cannot be expressed as an ordinary custom role.
  • Supervisor team write is narrowed by business rules to operator targets.
  • A custom-role deletion can affect active members and pending invitations and therefore requires review or reassignment.

Verify the result

Use this checklist before considering the work complete:

  • The chosen role is the least privilege that supports the documented work.
  • Owner, admin, operator, supervisor, and custom responsibilities are not confused.
  • Active members and pending invitations were reviewed before role deletion or reassignment.
  • The affected teammate confirmed effective navigation and actions after the change.

Troubleshooting

A teammate can read but not edit

Review the section level. Read intentionally omits write actions, while write includes read. Change the role only after confirming the edit responsibility is legitimate.

A custom role cannot be deleted

Review the error for active members and pending invitations using the role. Reassign them to an approved role, then complete deletion through the supported flow.

A supervisor cannot change another role

This is expected. Supervisors can invite, remove, or cancel only operator targets and cannot edit roles or manage custom roles. Ask an administrator or owner.

Related guides

Was this article helpful?