The rights table
Rights are the rows, roles are the columns, and every crossing is a checkbox.
Two rights are deliberately not free to hand out:
- Billing belongs to the Owner alone.
- Change approval requirement is Admin and Owner only. A right that loosens a safety lock must not itself be grantable, or a member could be given the right to take the lock off themselves. A lock whose key can be handed around is not a lock.
Nothing changes by itself. The defaults reproduce exactly the behaviour
your workspace had before this feature existed. Your people keep what they
had until you tick something.
Roles of your own
Next to the table, Add role creates one — “Accounting”, “Reception”, whatever your workspace calls it. Then tick what those people need. A new role starts with no rights at all. It inherits nothing: a role that quietly arrived with borrowed permissions would be the surprise, not the convenience. You can assign a custom role the same way as a built-in one, both when inviting someone and when editing them later. A role can only be deleted once nobody holds it — move those people first.Always needs approval
The same page carries a second list: action types that may never run unattended, whatever a flow says. Not even if someone sets the step to automatic in the editor, and not even after the trust ramp would otherwise have armed it. Out of the box that is three:
The line is who wrote it, not how far it travels.
Forwarding and webhooks are deliberately not on that list. A forward’s
recipient and a webhook’s URL are typed into the editor by a person; the AI
only decides whether the category matches, never where the thing goes. Both
therefore mature through the trust ramp like
any other rule.
You can still tick them. Anyone who wants every forward or every webhook call
reviewed sets the checkbox — that is what the setting is for. Be aware that
ticking webhook is one-way: a webhook cannot show a preview, so a locked
one stays a queue item and the AI-maturity page shows it as Locked instead of
offering a button that could only fail.