The three roles
Every teammate in your workspace has exactly one role: Owner, Admin, or Agent. Roles form a ladder — owner outranks admin, admin outranks agent — and each role can do everything the roles below it can, plus more. You can see and change anyone’s role from Settings → Agents (see Change an agent’s role or details).
Owner
The person who created the workspace. There’s exactly one owner, and the role can’t be reassigned from the Agents list — the owner’s account can’t be disabled or deleted (see Deactivate or remove an agent). Only the owner can see and manage:
- Billing
- Branding and the custom domain
- AI features and Instant answers
- Email intake and the chat Widget
- Integrations — API keys, Webhooks, Account linking, and the Sandbox
- Support hours, Automations, and Images & Files
- The Account section (name, email, data export, and account/content deletion)
None of these appear in an admin’s or agent’s gear-icon Settings menu at all. The owner is also the only one who can turn on the workspace-wide “require two-factor authentication” policy, and only a platform operator — not even the owner themselves — can reset the owner’s own 2FA.
Admin
A trusted teammate who helps run the workspace day to day, without owner-level access to billing, branding, or integrations. Promote someone by checking the box labelled “Admin — can manage agents, ticket types, and routing” when you edit them. Concretely, an admin can:
- Open Settings → Agents: add new agents, edit any agent’s full name, email, and handle, promote or demote other admins, disable, delete, and reset another agent’s 2FA (not the owner’s).
- Open Settings → Agents → Routing: set up and change auto-assignment rules (see Set up ticket routing).
- Open Settings → Tickets → Types: create, rename, recolor, reorder, and delete ticket types.
- Everything an Agent can do (below).
An admin cannot reach Billing, Branding, AI features, Email intake, the Widget, Integrations, Support hours, Automations, Images & Files, or the Account section — those stay owner-only, and don’t appear in an admin’s Settings menu.
Agent
The default role every new teammate gets when you add them (see Invite an agent). An agent works tickets — viewing, replying to, assigning, and closing them — uses shared canned-response Templates, and manages their own Profile, Communication preferences, and Security (their own password-free sign-in, 2FA, and passkeys). An agent’s gear-icon Settings menu won’t list Agents at all, and opening Tickets shows only Templates — Types stays admin-and-above only.
Where role affects what you see
The gear-icon Settings menu only lists the sections your role can reach — an agent’s menu is the shortest, an admin’s adds Agents (with Routing) and Types, and the owner’s includes everything above. If a teammate says they can’t find a setting that this documentation describes, check their role first.