Skip to content

Roles and permissions

Every person in your workspace has one of four roles: Owner, Admin, Agent or Viewer. Each role can do everything the role below it can, and more. Overdesk enforces roles on its servers, not only in the dashboard.

What each role adds

RoleWhat it adds
ViewerReads drafts, reports, analyses, the knowledge base and the rest of the dashboard, but cannot act on drafts or change settings.
AgentWorks on drafts in Overdesk (edit, re-draft and discard), starts a draft for a conversation, generates reports, runs analyses, acknowledges alerts and opens issues from a conversation.
AdminChanges settings, Guardrails and Customize AI, manages schedules, runs jobs and syncs by hand, connects and disconnects integrations, invites and removes people, and erases a customer's data on request.
OwnerManages the plan and billing, promotes existing members to Admin, deletes archived reports and deletes the workspace.

Three settings tabs, Notifications, Developers and Privacy & Data, appear only for admins and the owner.

The owner

Each workspace has one owner: the person who created it. The owner cannot be removed, and the owner role cannot be given to anyone else. Only the owner can choose a plan or change billing; everyone else sees a note that only the workspace owner can change plans.

Changing roles

Admins and the owner change a person's role from the menu beside their name on the Team page. Only the owner can make an existing member an Admin, and the owner's own role cannot be changed.

A role change takes effect the next time that person signs in, and a session lasts up to 24 hours. To cut off someone's access at once, remove them instead: that ends their sessions straight away. See Inviting and removing people.

Roles and Slack

Roles govern the Overdesk dashboard. Overdesk does not match Slack users to Overdesk roles, so anyone in your Slack workspace who can use the /overdesk command can ask for reports and start drafts with it. Drafts started this way still wait unsent in your help desk. See Slash commands.