Workspace
Roles and Permissions
InsightfulPipe has four workspace roles: Owner, Administrator, Operator and User. Owners, administrators and operators can connect accounts and run write actions; only owners and administrators manage members; only owners manage billing; users can only view and query the accounts they are granted.
Owner
- Everything an administrator can do
- Manages billing: subscribe, update payment and cancel
- Renames and deletes the workspace
- The only role that can make someone an owner
Administrator
- Invites members, changes roles and removes members with a role no higher than their own
- Grants accounts to User members on Manage Account Access
- Views billing
- Everything an operator can do
Operator
- Connects and manages accounts, brands and prompts
- Runs read and write actions through MCP and the CLI
- Chooses which actions each connected account exposes (Configure actions for this account)
- Cannot manage members or billing
User
- Views and queries only the accounts an owner or administrator grants
- Always read-only: write actions are refused with "Only operators, admins, and owners can execute write operations."
- Cannot change connector credentials, billing or workspace settings
Rules that apply to everyone
- An action runs only if it is enabled for the account and your role allows it.
- Read Only connections never run write actions, whatever your role.
- Nobody can change their own role, and any member can leave the workspace.
Tips
- Start people as User or Operator and raise the role when needed.
- Keep at least two owners.
Related: Inviting Members, Managing Members, Managing Connections.