Roles
Control what each team member can see and do in graph8 with role-based permissions.
Default Roles
graph8 ships a set of built-in roles tuned to common revenue functions. Each one comes pre-configured with sensible permissions, and you can clone or adjust any of them with custom roles.
| Role | Designed for |
|---|---|
| Admin | Full access to every feature, all data, and all settings (users, roles, billing, integrations). |
| CRO | Org-wide revenue visibility — reads all records and sees every conversation and transcript; limited write for coaching context. |
| Sales Manager | Team oversight with full read/write across all records. |
| SDR Manager | Leads the SDR team — team-scoped read/write on contacts, campaigns, tasks, mailboxes, and phone numbers; can assign leads. |
| Account Executive (AE) | Works an assigned book — reads and edits their own contacts, companies, and deals (including close-won/lost), with broad list visibility. |
| SDR | Outbound prospecting — reads and writes their own contacts and lists; hands deals off to an AE. |
| Commission SDR | Marketplace SDR with strict row-level isolation — reads and writes only their own records, no settings access. |
| CSM | Owns existing customer relationships — renewals, expansion, and customer meetings on customer-revenue pipelines. |
| Campaign Manager | Generates pipeline through campaigns, forms, and inbound; tracks attribution from their programs. |
| Support Agent | Replies to support conversations — own scope on contacts they touch, team scope on the support inbox, no deals. |
| Finance | Revenue read-only (all deals and companies for reporting) plus billing, credits, and invoicing. |
| View Only | Read-only across team records — cannot create, edit, delete, or change settings. Useful for executives, auditors, and analysts. |
The Admin role (and the marketplace Service Provider role) are locked — their permissions can’t be edited, so you always have a guaranteed full-access role.
Permissions
Permissions fall into two groups: per-object scopes (the CRM and engagement objects) and capability toggles (workflows, billing, settings, and team management). Both are configured per role in the role editor grid at Settings → Roles.
Object scopes
For each object below, a role gets an independent View scope and Edit scope, plus optional Delete, Assign, and Manage toggles:
| Scope | Meaning |
|---|---|
| Off | No access to this object |
| Own | Only records the user owns or is assigned to |
| Team | Records owned by anyone on the user’s team |
| All | Every record in the organization |
| Manage | Same as All, and also includes records that have no owner |
View and Edit are set separately, so a role can read at one scope and write at a narrower one (for example, View = Team, Edit = Own). Delete, Assign (reassign owners), and Manage are destructive or escalation actions and are flagged Critical in the editor.
The objects with per-row scoping are:
Contacts · Companies · Deals · Campaigns · Lists · Sequences · Tasks · Meetings · Mailboxes · Phone Numbers · Inbox Workspaces · AI Agents
Capability toggles
Non-object permissions are grouped into capability areas:
| Area | Toggles |
|---|---|
| Workflows | View · Run · Manage |
| Billing | View Credits · Purchase Credits · Manage Billing |
| Settings | Access Admin · View · Edit |
| Users | View · Edit Own · Edit All · Invite · Manage |
| Roles | Manage Roles |
| Teams | View · Manage |
Access Admin is the master gate for the entire Settings area — a role without it can’t reach any settings page, regardless of the more granular toggles. By default it’s on for Admin, GTM Engineer, and Finance; admins can grant it to other roles on demand.
How scopes affect what users see
A user’s role scope determines which records appear in their lists and detail pages — an Own-scope user sees only their own records, a Team-scope user sees their team’s. graph8 is rolling enforcement out object-by-object, so if a list looks narrower (or a page is hidden) than before, check the user’s role scope for that object in the role editor.
Custom Roles
Create roles tailored to your organization’s structure.
Creating a Custom Role
- Go to Settings → Roles
- Click Create Role
- Name the role and add a description
- Set the View/Edit scope and action toggles for each object, plus the capability toggles
- Save
Editing a Custom Role
- Find the role in the list
- Click Edit
- Adjust permissions as needed
- Save — changes apply immediately to all users with this role
Deleting a Custom Role
- Find the role in the list
- Click Delete
- Reassign users currently on this role to another role
- Confirm
Assigning Roles
Roles are assigned when inviting users or from the Users page:
- On invite — select the role in the invitation dialog
- After join — change the role from Settings → Users by clicking the role dropdown next to any user
A user can have only one role at a time. Changing roles takes effect immediately.
Frequently Asked Questions
Can I create a role with admin access to just one feature?
Yes. Custom roles let you toggle permissions per feature area. For example, you could create a “Sequence Manager” role with full access to sequences but read-only access to everything else.
What happens when I change someone’s role?
The change takes effect immediately. The user’s current session updates to reflect the new permissions. No logout is required.
Can I duplicate an existing role?
Use the Duplicate option next to any role to create a copy. Rename it and adjust permissions as needed.
Why can’t I grant a permission I don’t have myself?
To prevent privilege escalation, a non-admin can only create, edit, or assign roles that grant permissions they already hold. If you try to give a role a permission you lack, the change is rejected. Organization Owners and Admins are exempt and can grant anything.
Why can’t I edit the Admin role?
The Admin role (and the marketplace Service Provider role) are locked so there’s always a guaranteed full-access role and the marketplace flows keep working. Create a custom role if you need a tailored high-access role.