> ## Documentation Index
> Fetch the complete documentation index at: https://docs.digifist.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & Permissions

> Role-based access control for every team member in your Galantis workspace.

Galantis uses a role-based permission system to control what each team member can see and do across the platform. Every user in your workspace is assigned a role, and each role maps to a specific set of granular permissions. Roles are assigned when inviting a team member and can be updated at any time by an Owner or Admin.

## What this covers

* All available roles and their access levels
* How roles relate to Inbox access specifically
* Where to manage team member roles

## Roles

<Tabs>
  <Tab title="Owner & Admin">
    **Owner**

    Full access to every feature and setting in the workspace, including billing management. Only one Owner role exists per workspace. The Owner is the merchant who installed the app.

    ***

    **Admin**

    Full access to all platform features except billing management. Use this role for trusted team leads who need to configure campaigns, automations, templates, and the Inbox without access to subscription or payment settings.
  </Tab>

  <Tab title="Marketing">
    **Marketing Manager**

    Access to Campaigns, Automations, Templates, and Audience. This role covers the full marketing workflow — building automations, creating and submitting templates, managing segments and lists, and launching campaigns.

    ***

    **Campaign Operator**

    Can create and send campaigns. Does not have access to automation building, template creation, or audience management beyond selecting from existing lists and segments.

    ***

    **Content Creator**

    Can create and edit templates only. Use this role for team members responsible for copywriting and template submission who should not have access to campaign sending or automation configuration.
  </Tab>

  <Tab title="Analytics & Data">
    **Analyst**

    Read-only access to analytics across the platform. Can view campaign performance, automation activity, and inbox metrics. Cannot create, edit, or send anything.

    ***

    **Data Analyst**

    Read-only access to customer data and reports. Can view contact profiles, segment membership, and audience data. Cannot access campaign or automation analytics.
  </Tab>

  <Tab title="Support">
    **Support Agent**

    Access to the Inbox only. Can view, assign, and reply to conversations. Has no access to campaigns, automations, templates, audience, or analytics.

    This is the correct role for dedicated support team members whose work is limited to handling customer conversations. Each Support Agent seat is billed at **\$19 per seat per month** (Scale and Enterprise plans include 1 seat in the plan price) — see [Inbox Add-on Billing](/galantis/whatsapp/billing/add-ons/inbox).

    ***

    **Viewer**

    Read-only access across the entire platform. Cannot take any action. Use this role for stakeholders who need visibility into the workspace without the ability to modify anything.
  </Tab>
</Tabs>

## Role summary

| Role                  | Campaigns | Automations | Templates   | Audience  | Inbox     | Analytics | Billing |
| --------------------- | --------- | ----------- | ----------- | --------- | --------- | --------- | ------- |
| **Owner**             | ✓         | ✓           | ✓           | ✓         | ✓         | ✓         | ✓       |
| **Admin**             | ✓         | ✓           | ✓           | ✓         | ✓         | ✓         | —       |
| **Marketing Manager** | ✓         | ✓           | ✓           | ✓         | —         | ✓         | —       |
| **Campaign Operator** | Send only | —           | —           | View only | —         | —         | —       |
| **Content Creator**   | —         | —           | Create/edit | —         | —         | —         | —       |
| **Analyst**           | Read only | Read only   | Read only   | Read only | Read only | Read only | —       |
| **Data Analyst**      | —         | —           | —           | Read only | —         | Read only | —       |
| **Support Agent**     | —         | —           | —           | —         | ✓         | —         | —       |
| **Viewer**            | Read only | Read only   | Read only   | Read only | Read only | Read only | —       |

<Note>
  Galantis uses over 90 granular permissions to control access across the platform. The table above represents the functional access level per role. If you need a custom permission configuration that does not map to an existing role, contact Galantis support.
</Note>

## Managing team members

Team members are invited and assigned roles under **Settings → Team**. Roles can be changed at any time by an Owner or Admin. Changing a role takes effect immediately — there is no pending or confirmation step.

## Best practices

* **Assign the most restrictive role that covers the team member's responsibilities.** A marketing manager who only sends campaigns does not need the Marketing Manager role — Campaign Operator is sufficient.
* **Reserve Owner access carefully.** The Owner role cannot be duplicated. If the Owner account becomes inaccessible, escalate to Galantis support for workspace recovery options.
* **Use Support Agent for all inbox-only team members.** This role is purpose-built for support workflows and prevents accidental access to campaign or automation configuration.
* **Review team roles periodically.** When team members change responsibilities or leave, update or remove their access promptly.

## Related guides

* [Assignment & Routing](./assignment-routing) — How agent assignment works in practice
* [Inbox Add-on Billing](/whatsapp/billing/add-ons/inbox) — Per-seat billing for Support Agent roles
