Roles
Define custom roles with specific permissions to match your organization's structure and workflow.
Built-in Roles
Expedify comes with four standard roles:
Owner
- Full Access: Complete control of organization
- Billing: Manage subscription and payments
- Users: Add/remove any user including admins
- Settings: Configure all organization settings
- Cannot be removed: Every org needs at least one owner
Admin
- Manage Users: Add/remove members and viewers
- Access Data: View and edit all CRM data
- Workflows: Create and manage all workflows
- Settings: Access most settings (not billing)
- Analytics: Full access to reports and dashboards
Member
- CRM Access: Create and edit assigned items
- Workflows: Execute existing workflows
- Limited Settings: Personal settings only
- Collaboration: Comment, share, and collaborate
- Default Role: Standard role for team members
Viewer
- Read-Only: View data without editing
- Dashboards: Access reports and analytics
- No Workflows: Cannot execute workflows
- No Creation: Cannot create items
- Guest Access: Ideal for stakeholders
Custom Roles
Create roles tailored to your organization:
Creating a Custom Role
- Go to Settings → Roles
- Click Create Custom Role
- Enter role details:
- Role Name: e.g., "Sales Manager"
- Description: What this role is for
- Base Role: Start from existing role
- Configure permissions (see below)
- Click Create Role
Permission Categories
CRM Permissions
- Contacts: View, Create, Edit, Delete, Export, Import
- Companies: View, Create, Edit, Delete, Export, Import
- Deals: View, Create, Edit, Delete, Export, Import
- Tasks: View, Create, Edit, Delete, Export, Import
Channel Permissions
- Campaigns: View, Create, Edit, Send, Delete
- Templates: View, Create, Edit, Delete
- Segments: View, Create, Edit, Delete
- Inbox: View, Reply, Assign
Automation Permissions
- Workflows: View, Create, Edit, Delete, Execute
- Executions: View, Cancel, Retry
- AI Evaluation: View, Create, Edit
- Knowledge Base: View, Create, Edit, Delete
Team Permissions
- View Team: See team member list
- Invite Users: Send invitations
- Manage Members: Edit member details
- Assign Tasks: Assign to team members
- View Activity: Team activity logs
Settings Permissions
- Organization: View, Edit business info
- Integrations: View, Connect, Configure
- API Keys: View, Create, Delete
- Webhooks: View, Create, Edit, Delete
- Billing: View, Manage subscription
Analytics Permissions
- Dashboards: View, Create, Edit, Delete
- Queries: View, Create, Edit, Execute
- Charts: View, Create, Edit, Delete
- Export Reports: Download analytics data
Data Visibility
Control what data users with this role can access:
All Organization Data
- See everything in the organization
- Good for managers and admins
Team Data Only
- See data for assigned team
- Requires team structure setup
- Good for department heads
Owned Data Only
- See only items assigned to them
- Most restrictive option
- Good for individual contributors
Custom Rules
- Define complex visibility rules
- Based on filters and conditions
- Advanced configuration
Example Custom Roles
Sales Manager
Base Role: Admin CRM: Full access Campaigns: View only Workflows: View, Execute Team: Manage sales team members Visibility: Sales team data
Marketing Coordinator
Base Role: Member CRM: View, Create contacts Campaigns: Full access (create, edit, send) Workflows: Execute only Team: View team Visibility: All data (read-only for CRM)
Customer Support Rep
Base Role: Member CRM: View, Edit contacts and tasks Campaigns: View only Workflows: Execute support workflows Team: View team Visibility: Assigned contacts only
Finance Analyst
Base Role: Viewer CRM: View deals and payments Campaigns: View campaign spend Workflows: View only Team: View team Analytics: Full access Visibility: All data (read-only)
Regional Manager
Base Role: Admin CRM: Full access Campaigns: View, Create, Send Workflows: Full access Team: Manage regional team Visibility: Region-specific data (custom rule)
Managing Roles
Assign Role to User
- Go to Settings → Users & Teams
- Find the user
- Click Edit
- Select role from dropdown
- Click Save
Edit Custom Role
- Go to Settings → Roles
- Find the custom role
- Click Edit
- Update permissions as needed
- Click Save Changes
- All users with this role are updated automatically
Delete Custom Role
- Go to Settings → Roles
- Find the custom role
- Click Delete
- Choose what to do with users:
- Reassign to another role
- Convert to Member role
- Confirm deletion
Note: Built-in roles (Owner, Admin, Member, Viewer) cannot be deleted.
Role Hierarchy
Understand permission precedence:
Owner (Highest)
↓
Admin
↓
Custom Roles (varies)
↓
Member
↓
Viewer (Lowest)
Rules:
- Higher roles can manage lower roles
- Owners can manage everyone
- Admins cannot manage other admins or owners
- Custom roles cannot elevate above their base role
Best Practices
- Start Simple: Use built-in roles first
- Create as Needed: Only add custom roles when required
- Document Roles: Maintain list of who has which role
- Regular Reviews: Audit roles quarterly
- Test Thoroughly: Verify permissions work as expected
- Least Privilege: Give minimum permissions needed
Use Cases
Growing Startup (5-10 people)
- Use built-in roles only
- Owner for founder
- Admin for co-founders
- Member for everyone else
SMB (20-50 people)
- Add 2-3 custom roles
- Sales Manager (manages sales team)
- Marketing Lead (full campaign access)
- Support Lead (manages support team)
Enterprise (100+ people)
- Multiple custom roles per department
- Regional managers (territory-based access)
- Department heads (department-specific permissions)
- Specialists (function-specific access)
Security Considerations
- Role Explosion: Don't create too many roles (max 10-15)
- Permission Drift: Regularly audit role permissions
- Over-Privileged Users: Monitor users with elevated access
- Role Documentation: Keep record of role purposes
- Change Management: Track role permission changes
Troubleshooting
User can't perform action?
- Check their assigned role
- Verify role has required permission
- Check data visibility settings
- Review any custom restrictions
Too many permission requests?
- May need new custom role
- Review existing role definitions
- Consider adjusting base roles
Roles getting complicated?
- Simplify role structure
- Consolidate similar roles
- Use data visibility instead of role proliferation
Support
Need help creating custom roles? Contact us through Settings → Support.