Team & Permissions
Use role-based access to control what each member of your organization can do, with Owner, Admin, and Editor roles.
Owlat uses role-based access to control what each member of your organization can do. Whether you're a solo operator or a growing team, understanding roles helps you delegate safely and keep your account secure.
Roles
Every team member has one of three roles:
- Owner — Full control over the organization, including destructive actions like deleting the org and changing other members' roles. Owner cannot be assigned when inviting someone, but ownership can be handed off later via Transfer Ownership, which promotes the chosen member to Owner and demotes the current Owner to Admin.
- Admin — Day-to-day operational control. Admins can create and edit content (templates, campaigns, contacts, topics), manage settings, send campaigns, invite members, and remove Editors.
- Editor — Runs the marketing send pipeline. Editors can create, edit, schedule, and send campaigns — but only from the curated list of campaign senders an Admin has approved. They can read templates, segments, and media to build a campaign, send test emails, read the knowledge graph, and participate in team chat. Editors cannot curate the campaign-sender list, manage contacts or topics, or change settings.
What each role can do
| Capability | Owner | Admin | Editor |
|---|---|---|---|
| Create, edit, and send campaigns | Yes | Yes | Yes (from approved senders) |
| Create and edit templates | Yes | Yes | View only |
| Send test emails | Yes | Yes | Yes |
| Curate the campaign-sender list | Yes | Yes | No |
| Manage contacts and topics | Yes | Yes | View only |
| Invite members and remove Editors | Yes | Yes | No |
| Change a member's role | Yes | No | No |
| Remove Admins or Owners | Yes | No | No |
| Manage settings, API keys, and webhooks | Yes | Yes | No |
| Delete the organization | Yes | No | No |
Admins manage members in a limited way: they can send invitations and remove Editors, but only an Owner can change a member's role or remove another Admin or Owner.
Managing your team
Team management lives under Settings > Team Members (the page heading reads "Team Members"; the browser tab title is "Team Management").
Invite members
- Open Settings > Team Members.
- Click Invite Member.
- Enter the person's email address and pick a role — the invite modal offers Admin or Editor (Owner is not assignable).
- They'll receive an invitation link to join your organization. Invitations expire after 7 days.
Reserve a personal mailbox (Postbox)
When you have at least one verified sending domain and the Postbox feature is enabled, the invite modal shows an optional "Also reserve a personal mailbox for this user" checkbox. Check it to pick a local part and verified domain (for example marcel@yourdomain.com); the mailbox is created automatically when the invitee accepts the invitation.
The mailbox checkbox only appears when both conditions are met: a verified domain exists and the Postbox feature flag is on. See Postbox — Personal Email for more.
Change a member's role
Only an Owner can change roles. Open Settings > Team Members, use the per-member actions menu (the … button), and switch the member between Admin and Editor. An Owner cannot directly change their own role, but can hand off the role using Transfer Ownership (per-member actions menu), which makes the chosen member the Owner and demotes the current Owner to Admin.
Cancel a pending invitation
Pending invitations appear in the Pending Invites section with their expiry countdown. Click the cancel (×) action to revoke an invite before it's accepted — the invite link stops working immediately. Owners and Admins can cancel invites.
Remove a member
- Open Settings > Team Members.
- Click the remove action next to the member, then confirm. Owners can remove anyone except themselves; Admins can remove Editors only.
Removing a member is immediate. They will lose access to your organization right away.
Governance recommendations
- Keep owner and admin seats limited to people who need operational control
- Use Audit Logs to review sensitive operations
- Rotate API keys and webhook secrets on a regular schedule
- Review team access during employee offboarding
Next steps
- API Keys & Webhooks — manage integration credentials
- Audit Logs — track what happened and when