MadderHelp Request early access

Roles and members

Four built-in roles — owner, admin, operator, analyst — plus custom roles; only owners and admins can approve spend.

Checked 6 Sep 2026

Inviting someone takes a minute.

Before you start#

  • To invite or remove people you need Invite & manage members: owner or admin.
  • To change someone's role you must be the owner.

1. The built-in roles#

RoleCan
OwnerEverything: approve spend, connect and disconnect sources, members, billing, workspace settings, the danger zone. One owner per workspace.
AdminApprove spend, connect and disconnect sources, invite and manage members, billing, workspace settings. Not the danger zone.
OperatorView reports and draft and run campaigns. Cannot approve spend, touch sources, members or billing.
AnalystView reports only. No changes.

There is no separate "viewer" role: Analyst is the read-only seat. Settings → Roles & access also lets an owner or admin shape a custom role by switching capabilities on or off over a base tier — for example an operator who may also Approve spend.

2. Who may approve#

Approving is a human act. The capability is Approve spend, held by owner and admin by default. The agent and the executor can never approve; the database refuses it. A person without the capability can read every proposal but not act on it.

3. Invite someone#

Settings → Members → Invite. The dialog Invite people takes Email addresses (several, separated by commas or spaces) and a role: admin, operator or analyst. Press Send invites. Each invite is a link that expires after 14 days; it appears under Pending invitations where you can resend or Revoke invitation. The invitee gets access as soon as they accept.

4. Change a role or remove someone#

From a member's menu the owner can change the role; owners and admins can Remove from workspace. Removing revokes access at once. Campaigns and sources that person connected stay in the workspace.

5. What each role sees#

Everyone in the workspace sees the same campaigns, proposals and reports. Roles gate actions, not visibility, with one exception: sections that need a capability you lack show read-only for your role.

If it doesn't work#

  • "Only owners and admins can disconnect a source" — ask an owner or admin, or ask for a custom role with Connect & disconnect sources.
  • The invite link says it is used or expired — resend it from Pending invitations.
  • You cannot invite an owner — by design. Ownership is transferred, not invited.
  • A member cannot see the Approve button — their role lacks Approve spend.