Workspace
Updated

Roles and Permissions

InsightfulPipe has four workspace roles: Owner, Administrator, Operator and User. Owners, administrators and operators can connect accounts and run write actions; only owners and administrators manage members; only owners manage billing; users can only view and query the accounts they are granted.

Owner

  • Everything an administrator can do
  • Manages billing: subscribe, update payment and cancel
  • Renames and deletes the workspace
  • The only role that can make someone an owner

Administrator

  • Invites members, changes roles and removes members with a role no higher than their own
  • Grants accounts to User members on Manage Account Access
  • Views billing
  • Everything an operator can do

Operator

  • Connects and manages accounts, brands and prompts
  • Runs read and write actions through MCP and the CLI
  • Chooses which actions each connected account exposes (Configure actions for this account)
  • Cannot manage members or billing

User

  • Views and queries only the accounts an owner or administrator grants
  • Always read-only: write actions are refused with "Only operators, admins, and owners can execute write operations."
  • Cannot change connector credentials, billing or workspace settings

Rules that apply to everyone

  • An action runs only if it is enabled for the account and your role allows it.
  • Read Only connections never run write actions, whatever your role.
  • Nobody can change their own role, and any member can leave the workspace.

Tips

  • Start people as User or Operator and raise the role when needed.
  • Keep at least two owners.

Related: Inviting Members, Managing Members, Managing Connections.

Need help?

If you need help connecting a source or setting up an AI workflow, the team can help you get from first sync to production faster.