Skip to content

Roles, permissions & brand access

Buzzator controls what each teammate can do with two independent layers: a platform role that sets their baseline permissions, and optional per-brand access grants that limit which brands they can touch. This page explains both, plus how owners can customize the permission set.

The four roles

Every member has exactly one platform role:

Role Purpose
Owner The workspace owner. Has every permission, including billing. There is exactly one owner path of authority, and the role can't be reassigned or removed.
Admin Operational lead. Publishes, schedules, manages the team and Brand Brain — bounded by the brands they're granted.
Editor Content creator. Writes, edits, comments on, and approves posts, but can't publish or schedule.
Viewer Read-only access to content and analytics.

What each role can do

Capability Owner Admin Editor Viewer
View analytics & storyboard
Comment / post activity
Create & edit posts (drafts)
Approve posts
Publish now
Schedule posts
Bypass AI review
Edit Brand Brain
Wipe Brand Brain
Manage team
Manage billing

Bypass AI review lets a member schedule an unreviewed AI-generated post without a separate human-review step — it records them as the self-approver and still leaves an audit trail. See AI-review & compliance.

Billing can't be delegated

Manage billing is owner-only by design. It's the one capability that can never be granted to another role, even through custom permissions.

Per-brand access grants

A member can be scoped to a subset of your brands instead of the whole workspace.

  • Owners always have access to every brand, no matter what.
  • Admins have access to all brands unless the owner has scoped them.
  • Editors and viewers can be granted access brand by brand. For each brand you choose No access, Viewer, Editor, or Admin.

Unlisted brands are denied

Once a non-owner has any per-brand grants configured, they are limited to exactly the brands listed — any brand not in their grant is treated as "no access," not "inherited." A member with no grants at all is treated as org-wide (unrestricted). Only an owner can grant the brand-level Admin role.

You manage per-brand grants from the Team settings member table — see Managing your team.

Customizing role permissions (owners)

Owners can tailor what the Admin, Editor, and Viewer roles are allowed to do, from the Access Management matrix in Team settings.

  • Custom permissions add to a role's defaults — they never remove a role's built-in capabilities.
  • Owner-only capabilities (like billing) can't be handed to a lower role.
  • The Owner role always keeps every permission and can't be edited.

Give changes a moment

A role or permission change can take up to about a minute to fully propagate to every part of the app.