Workspace Roles
Every workspace you create has an Owner, Admin, and Collaborator role, each with a fixed set of permissions over billing, the collaborator roster, and resource access. Owners can grant a non-owner collaborator extra access, or take some away, without changing their overall role. A Roles page shows your own effective access and the full permission matrix so nobody has to guess what they can do.
A workspace is a shared space: your AI employees, their conversations, your training data, and your billing all live inside it. As soon as more than one person works in that space, someone has to decide who can invite the next person, who can touch billing, and who can only use what is already there. Workspace Roles is the answer built into every workspace from the day it is created, not a separate add-on you have to configure.
There are three roles. Owner has full control: inviting and removing people, billing, workspace settings, and destructive actions like deleting the workspace. Every workspace always keeps at least one Owner, so control can never accidentally disappear. Admin can invite Collaborators, remove or demote anyone who is not an Owner, and manage the resource-sharing settings covered below, but cannot touch billing, workspace settings, or grant Owner or Admin access to anyone else. Collaborator can use the workspace normally, chat with employees, and open the Drive files, Drive documents, and CRM contacts that are workspace-visible or shared directly with them, but cannot manage the roster, billing, or another person's access.
What makes this different from a single fixed permission list is the override layer sitting on top of the three roles. An Owner can open Customize Access for any individual non-owner collaborator and grant or revoke specific things (seeing certain teams, sending invitations, managing other non-owner members, sharing resources) without moving that person into a different role. A Collaborator who needs to invite new teammates does not have to become an Admin to do it, and an Admin who should not be allowed to remove people can have that one permission pulled back. Two survival-critical powers, closing the workspace's subscription and controlling the organization itself, are never delegable this way; they stay with an Owner regardless of any override, so a per-person tweak can never accidentally hand away the workspace.
The Roles page in Settings makes this transparent instead of implicit. It shows your own effective access (your base role plus any overrides applied to you), the full permission matrix for all three roles, and a Request Access Review button that notifies the Owner when you find you need more than your current role grants. Nobody has to ask a teammate or guess from a support conversation whether they are allowed to do something; the page answers it directly.
What Each Role Can Do
Owner: full access to the workspace plus collaborator management, resource access management, and billing and workspace control. A workspace always keeps at least one Owner.
Admin: full access to the workspace, can manage collaborators except Owners, and can manage resource access, but has no billing or workspace-settings control.
Collaborator: can use workspace-visible resources and anything shared directly with them, but cannot manage the roster, another person's access, billing, or workspace settings.
Per-Person Access Overrides
Beyond the three roles, an Owner can adjust individual access for any non-owner collaborator: team visibility, sending invitations, managing other non-owner members, and managing resource sharing can each be granted or revoked one person at a time.
This exists for the common case where someone's day-to-day responsibility does not match either full Admin or plain Collaborator. Billing control and workspace-level control are deliberately left out of the override system; those stay tied to the Owner role no matter what overrides are applied.
How It Works
Three roles, with per-person overrides an Owner controls
Roles are assigned when you invite someone: enter their email in Settings > Organizations > Members, choose Owner, Admin, or Collaborator, and send the invite. The role determines their baseline access to the collaborator roster, resource sharing, and billing from the moment they accept.
An Owner can go further for any individual non-owner collaborator through Actions > Customize Access, toggling specific permissions like inviting members, managing non-owner members, or managing resource access on or off for that one person, independent of their role label. Manage Billing and Manage Organization are excluded from these overrides on purpose, so no combination of per-person tweaks can strip an Owner of ultimate control.
Every collaborator can check Settings > Organizations > Roles at any time to see their own current permissions next to the full role matrix, and can request a review from the Owner directly from that page instead of asking around.
Use Cases
Bring on a client without handing over the business
Invite a client or contractor as a Collaborator so they can see the work and chat with your AI employees, without giving them any ability to touch billing, invite others, or change workspace settings.
Share day-to-day management without full Admin power
Make a trusted teammate an Admin so they can invite people and manage the roster while you keep the only Owner seat, so billing and the ability to delete the workspace stay in your hands.
Hand a single duty to one Collaborator
Use Customize Access to let one Collaborator invite new teammates or manage resource sharing, matching what they actually do day to day without promoting them to Admin.
Check your own limits before asking for help
Open the Roles page to see your effective access and the full permission matrix directly, then use Request Access Review to notify the Owner instead of guessing or interrupting a teammate.
FAQ
Who can invite new people to a workspace?
Owners and Admins can invite collaborators by default. A Collaborator can also invite people if an Owner has granted them the Invite Members override, even though inviting is not part of the base Collaborator role.
Can I give someone extra access without making them an Admin?
Yes. An Owner can open Customize Access for a specific Collaborator and grant individual permissions, such as inviting members or managing resource access, without changing their role from Collaborator to Admin.
Can an Admin remove or demote the Owner?
No. Admins can remove or demote any non-owner member, but they cannot act on an Owner, grant Owner or Admin access to anyone, manage billing, or change workspace settings.
What happens if the only Owner leaves the workspace?
A workspace is required to always retain at least one Owner, so ownership must be transferred to another member before the last Owner can leave or be removed.
Where do I check what I personally am allowed to do?
Open Settings > Organizations > Roles. It shows your effective access, including any per-person overrides an Owner has applied to you, alongside the full permission matrix for every role.
Where Workspace Roles fits
Workspace Roles is part of How you run the account itself.
Sign in the way your company already does, decide who can do what, and keep the money side legible. Credits, plans, invoices, referrals, and the controls that decide who reaches which part of the workspace.
Read the guide
More in Account & Billing
- Monthly Credits: Every paid plan comes with a pool of credits that refills automatically at the start of each billing period. Credits are the single unit that pays for everything your AI employees do: thinking, tool calls, media generation, voice, and meetings. There is nothing to top up manually each month; your allowance is just there again when the new period starts.
- Lifetime Credits (Free): Pick the Free plan and your workspace gets 2,000 credits in one grant, no card required. Those credits never reset and never expire; you spend them at your own pace across chat, tools, and media generation until they run out. It is a one-time bucket, not a monthly allowance, so it is meant for trying the platform before you commit to a paid plan.
- Buy Credits: Add credits to your workspace balance any time, on any plan, without changing your subscription. Pick from three one-time packs, pay by card through Stripe, and the credits land in your balance as soon as the payment clears.
- Upgrade & Downgrade: Move to a bigger plan the moment you need more credits or a higher employee cap, and the change takes effect immediately. Move to a smaller plan when you need less, and it takes effect at the end of your current billing period so you keep what you already paid for. Both happen from Settings, Subscription, no support ticket required.
- Promo Codes: Redeem a promotional code for a one-time, lifetime grant of bonus credits on top of your plan's monthly allowance. Enter a code at signup or any time afterward from Settings, Subscription, Get Free Credits. Each grant shows up in your Credit Grants history with its source, date, and amount, and one code can be redeemed once per workspace.
- Referrals: Share your personal referral link or invite someone by email, and you both get 1,000 free credits the moment they sign up. Track every invite from a dedicated Earn Credits page, and keep earning until you hit the 10-referral cap.
- Data Retention: Sistava deletes operational data on a fixed schedule instead of keeping it forever by default. A cleanup job runs every day and removes rows past their retention window: short-lived debug data within a week or two, working memory after 30 days of inactivity, and usage and activity history after two years. Chat messages, documents your employees write, and persistent notes are kept indefinitely unless you delete them yourself. There is no setting to change these windows; they apply the same way to every workspace.
- Google Sign-In: Sign in to Sistava with your Google account instead of creating a separate password. Choose Sign up with Google on the signup page and your workspace is ready after one approval, with your name and photo carried over automatically from Google. Because Google has already confirmed your email address, there is no verification email to chase before your AI employees can start working.
- Microsoft Sign-In: Sign up or sign in with your Microsoft account instead of creating a password. Sistava reads your Microsoft account's name, email, and profile photo to set up your account, and your Profile page shows Microsoft as your connected sign-in method. Because Microsoft has already confirmed the address belongs to you, the account counts as verified from the start and your employees can begin working straight away. Google sign-in and an ordinary email and password are the other two ways in.
- User Profile Picture: Upload a photo for your account so your teammates and AI employees see a real picture of you instead of initials. It shows up in chat, comments, and the collaborator list across every workspace you belong to. If you signed up with Google or Microsoft, your picture is pulled in automatically the first time you sign in, and you can replace it any time.
- Two-Factor Authentication: Add a second sign-in step to your Sistava account using any TOTP authenticator app, like Google Authenticator or Authy. Once enabled, a code from your app is required in addition to your password, so a leaked or guessed password alone is not enough to get in. Turning it on immediately signs out every other active session, so a session created before you enabled it cannot be used to bypass it.
- Feedback Board: Submit bug reports, feature requests, improvements, and questions from inside the app, then vote on what other users have asked for. Every item lands on one Community Board visible to the whole platform, sorted by vote count, so the most-wanted ideas surface for the team automatically.
Explore