Assign standard roles

Account Admins grant team members access to workspaces by assigning them workspace-level roles. A standard role comes with a defined set of permissions. To create roles with custom permission sets, check out Custom roles.

Overview

You can assign standard roles to team members from Workspace Settings or from Account Settings > Team Members.

A workspace-level role controls the set of permissions a team member has in a single workspace. We offer three standard roles:

  • Workspace Admin (full access)
  • Author (partial access)
  • Viewer (view-only access)

When you assign Author or Viewer roles, you choose whether to limit their access to sensitive data. This helps you keep your account as secure as possible.

Remember that before you specify workspace-level permissions, you have to choose an account-level permission: Account Admin or Member. Account Admins are always Workspace Admins in every workspace. This ensures Account Admins have full rights across each of your workspaces. Members can have different workspace-level roles for each workspace they have access to.

Workspace Admin

Workspace Admins have full access to all settings and features in a workspace. This is the only workspace-level role that can:

  • Import or export user data
  • Manage integrations
  • Manage Webhook configurations
  • Create, edit, or delete collections
  • Mark attributes as sensitive in the Data Index and hide them from Authors or Viewers

They cannot create or delete workspaces; only Account Admins can.

Author

Authors have partial access to workspace settings and features. They can manage some features like content and automations, but only view others like collections. They can create individual webhooks in automations, but can’t create or manage reusable webhooks in workspace settings.

Account and Workspace Admins can decide whether to hide sensitive attribute data from authors.

Authors with sensitive data hidden can't edit profiles

Authors with sensitive data hidden have the same functionality as authors who can view all data, with one exception: they can’t edit profiles.

Viewer

Viewers have no access to workspace settings and partial access to workspace features. They have view-only permissions to all workflows, content, and data in a workspace.

Account and Workspace Admins can decide whether to hide sensitive attribute data from viewers.

Compare permissions across standard roles

Workspace settings

PermissionWorkspace AdminAuthorViewer
General Workspace Settings
View
Update
Messaging Settings
View
Update
Email Suppression List
View
Unsuppress
Export
Language Settings
View
Update
Merge Options
View
Update
Message Limit
View
Update
Subscription Center
View
Update
Time Zone Match
Test
URL Parameters
View
Update
Webhook configuration
View
Create
Update
Delete

Journeys

PermissionWorkspace AdminAuthorViewer
Send messages
Automations
Create
View
Update
Delete
Assign/Unassign Tags
Broadcasts
Create
View
Update
Delete
Assign/Unassign Tags
Transactional Messages
Create
View
Update
Delete
Assign/Unassign Tags
Message activity
View
Profiles
Create
View
Update11
Delete
Object Types
Create
View
Update
Delete
Objects and Relationships
Create
View
Update
Delete
Segments
Create
View
Update
Delete
Import CSV
Assign/Unassign Tags
Geofences
Create
View
Update
Delete
Ad Audiences
Create
View
Delete
Integrate
Pause
Resume
Assign/Unassign Tags
Profile activity
View
Data Index
View
Update attribute descriptions
Export
Tags in the data index
Create
Update
Delete
Assign
Remove
Integrations
Create
View
Update
Delete
Data Import/Export
Import
Export
Message Library
View
Assets
View
Delete
Upload
Email Layouts
Create
View
Update
Delete
In-app Message Library
View
Snippets
Create
View
Update
Delete
Collections
Create
View
Update
Delete
Design Studio - Styles
View
Create
Update
Delete
Design Studio - Files
View
Export
Create
Update
Delete
Design Studio - Feedback
Feedback mode
Authors with sensitive attributes hidden cannot edit profiles

Hide sensitive attributes

Premium This feature is available for Premium plans. Enterprise This feature is available for Enterprise plans.

If you’re on a Premium or Enterprise plan, then Account and Workspace Admins can mark profile attributes as “sensitive” in the Data Index and decide whether to hide this data from team members. This redacts values but not attribute names from the workspace.

Mark attributes as sensitive

Account admins and workspace admins can mark profile attributes as sensitive in the Data Index. This redacts values but not attributes names from the workspace and helps ensure data privacy across team members. If you have a custom role that includes the Edit permission for the Data Index, you can also mark attributes as sensitive.

You can also mark event attributes as sensitive independently. In the Events tab, select an event to find its attributes and mark them as sensitive. Profile and event attributes are separate—marking a profile attribute as sensitive doesn’t automatically redact event attributes with the same name.

  1. In the Attributes tab, click an attribute.
  2. Click Edit in the panel.
  3. Click “Make sensitive.” To unhide sensitive attributes, select the box to uncheck it.

    Not seeing Make sensitive?

    Check that you’re an Account Admin or Workspace Admin in Team Members. If you are, then check whether you’re on a Premium or Enterprise plan or reach out to someone with billing access. Otherwise, you’ll have to upgrade for access.
  4. Click Save.
  5. Next, assign “Hide sensitive attributes” to team members.

Choose “Hide sensitive attributes” when assigning standard roles

After an admin marks attributes as sensitive in the Data Index, they must update Authors or Viewers so they can’t view these sensitive attributes:

  1. Go to Workspace Settings.
  2. Scroll to the bottom section “Who should have access?”
  3. Change the dropdown from “Show all attributes” to “Hide sensitive attributes” for each team member.

If you’re an Account Admin, you can also assign this from Team Members:

  1. Under Workspace level permissions, specify Author or Viewer for workspaces.
    /images/team-member-hide-sensitive.png
  2. Choose Hide sensitive attributes from the dropdown.
  3. Save or invite your team member.

These team members will now see values redacted for sensitive attributes. If they send test messages or webhooks from your workspace, those messages and responses will also contain redacted values.

Authors with sensitive data hidden can't edit profiles

Authors with sensitive data hidden have the same functionality as Authors who can view all data, with one exception: they can’t edit profiles.

Do you see the option Hide all attributes?

If so, this is a legacy feature and you can learn more about how this limits authors access to data and functionality.
Updated August 20, 2026