Permissions
Every area a team member can be granted, what each access level means, and how to scope someone's access to fit the job.
Permissions decide what a team member can see and do inside your tribe. Every area of the dashboard is its own row, and each row is set to one of three levels, so you can be as broad or as surgical as you like.
This page covers the levels, the capabilities that sit outside them, the full list of areas, and the role presets that fill it all in for you.
The three access levels
For every area, a member has exactly one of:
- All Access: view everything in the area and make changes. Create, edit, delete, send, publish, refund, and so on.
- Read Only: view everything in the area, with none of the buttons that change anything.
- No Access: the area is hidden. The link doesn't appear in their sidebar and they can't open it directly.
All Access always includes viewing. There's no state where someone can edit something they can't see.
Hidden, not greyed out
No Access doesn't leave a dimmed menu item behind. The area disappears from that member's sidebar. If you remove access while they're using it, they lose the page on their next click.
Capabilities that are not levels
Two things in the editor are checkboxes rather than dropdowns, because they are single jobs rather than a level of access. They sit indented under the area they relate to, and they work on their own:
- Door check-in, under Events. The person can scan tickets and read the door list for your events, and nothing else. Granting it does not open the Events area, and setting Events to All Access does not grant it.
- Approve timesheets, under Time Tracking. The person can approve other members' hours for payout. Logging your own hours is Time Tracking All Access. Approving someone else's is deliberately not the same thing.
Tick or untick these independently of the dropdown above them. Nothing about the dropdown changes them, and nothing about them changes the dropdown.
The areas you can grant
The Edit Permissions dialog lists every area in one column, in the order below. Each row gets its own dropdown set to All Access, Read Only or No Access.
| Area | What it covers |
|---|---|
| Websites | Your public website, its pages and theme, domains, installed apps and the messages sent through it |
| Smart Links | The link pages you share off-platform for releases and campaigns |
| Events | Shows, ticket types, event series and ticket orders |
| Products | Your store catalogue: merch, music, digital downloads, options, stock and shipping |
| Memberships & Posts | Membership tiers, members, member-only posts and community spaces |
| Emails | Campaigns, templates, lists, lead magnets and your sending settings |
| Scheduling | Coaching and bookings: what you offer, your availability, and who has booked |
| Courses | Courses and lessons, quizzes and certificates, cohorts and students |
| Streaming | Going live, broadcasts, channels and recordings |
| Blog | Blog posts and categories |
| Forms | The forms you embed and the answers people send |
| Collections | Your structured content collections and their entries |
| Ads | Advertising campaigns and the ad accounts behind them |
| Social Media | Connected social accounts, posts, the calendar, analytics, inbox, comments and social automations |
| Coupons | Discount codes for products, tickets and memberships |
| Offers | One-click checkout offers you attach to a purchase |
| Donations | Donations you've received and how you ask for them |
| Reviews | Customer reviews and moderating them |
| Affiliates | Partner programs, tracked links, commission rules and payouts |
| Deals | Your sales pipeline |
| Invoices | Invoices, payment links and documents sent for signature |
| Team | The Team page itself, meaning inviting, editing and removing members |
| Finance | Your earnings overview, transactions and expenses |
| Settings | Workspace settings, including its type, its language and the optional features |
| Contacts | Your contact list, segments, tags and the automations that run on them |
| Mira (AI agent) | Mira, your built-in copilot: her chat, her briefings and acting on her proposals |
| Projects | Projects, tasks, milestones, the board, reports, labels and custom fields |
| Time Tracking | Timers, manual entries and timesheets |
| Phone Numbers & SMS | Your phone numbers and the SMS sender registration |
| Voice Agent | The voice agent that answers your calls, plus call history, transcripts and recordings |
Two rows you no longer have to ask for
Contacts and Mira used to depend on the feature being switched on for your tribe. They're now ordinary rows on this list, so the permission is the whole of the gate. Ads is the one row that still appears only where advertising is available. If you don't see it and want it, ask us.
Not everything is on this list. Access to a knowledge base space or document is granted on the space or the document itself rather than here, so you won't find a row for it.
The money areas are owner-only
Finance and Invoices can only be granted by the workspace owner. If you're an admin editing someone's permissions, those two rows don't appear for you at all, so you can't grant what the system would refuse.
The owner grants them from the same dialogs everyone else uses. See "Adding financial access to an admin" below.
Role presets
Setting thirty rows by hand gets old fast, so the invite dialog and the edit dialog both open with a Role Preset dropdown. Pick one and the rows are filled in for you. You can still change any individual row afterwards.
Built-in presets
- Admin: everything except the financial areas. This one is special, see below.
- Content Manager: memberships and posts, blog, emails, courses, coaching, events, streaming, collections and the website.
- Store Manager: products, coupons, offers, donations, invoices, memberships and the website.
- Marketing: emails, smart links, forms, coupons and the website.
- Event Manager: events, streaming, emails and the website.
- Door Staff: the door check-in capability and nothing else. See below.
- Read Only: view-only across everything except the financial areas. Good for a stakeholder or an accountant who needs visibility without edit rights.
Any custom roles saved for your workspace appear in the same dropdown, under the built-in ones. Custom at the bottom means "I'm setting these by hand".
Admin is a live role, not a snapshot
Choosing Admin doesn't copy a list of permissions onto that person. It marks them as an admin, and the dashboard resolves what that means every time they use it.
The practical effect: an admin automatically gets new areas as TribeNest adds them, without you going back to re-grant anything. The dialog says as much on screen, under the preset dropdown.
Adding financial access to an admin
An admin has everything except Finance and Invoices. If you're the owner and you want one of them to have those too:
- Open the invite dialog, or the pencil on a member's row.
- Leave the Role Preset on Admin.
- Click Grant financial access… under the preset.
- Set Finance and Invoices to the level you want, then click Done.
- Send the invite, or click Save Permissions.
Only the owner sees that link. An admin managing the team never does.
The door-only team member
Door Staff is worth calling out because it's the narrowest role there is, and the most useful one to get right.
A door-only member holds one capability: scan tickets and read the door list. They can't open your events, see who bought what, email your attendees or cancel a show. When they sign in they see the Events group in the sidebar with a single item, Door, and that item lists the shows happening around now that they can scan into. Everything else is closed to them.
That is exactly what you want for someone hired for one night. Before this existed, handing a steward a scanner meant granting the whole Events area, which also lets them cancel the show and mail the attendee list.
Door access covers all of your events
The capability applies to your whole workspace, not to one show. A door-only member can scan into any of your events happening in that window. It never reaches anyone else's. If someone should only ever work one specific night, remove them after it.
See the door and box office for what the door screen actually does.
Setting permissions by hand
From the invite dialog or a member's edit dialog:
- Pick the closest Role Preset, or pick Custom.
- Click the pencil beside Permissions to open Edit Permissions.
- Set any row to All Access, Read Only or No Access.
- Tick a capability checkbox if the job needs one.
- Click Done to close the dialog.
- Click Send Invite, or Save Permissions for an existing member.
The moment you deviate from a preset, the Role Preset dropdown switches to Custom, so you can tell at a glance that you've moved off the template.
The line under Permissions summarizes what you've set, for example "5 all access · 3 read only · 1 special access · 4 restricted". Use it as a sanity check before you save. A capability is counted separately there, never folded into the other numbers, which is why a door-only member never reads as "No access".
How to scope a member's access
A few patterns that work well in practice.
Start narrow, widen as needed
Pick the smallest preset that covers most of the job, then add one row. Your store manager needs to send a "back in stock" email now and then, so start with Store Manager and flip Emails to All Access. Everything else stays closed.
Mix read and write
Not every row is all or nothing. A bookkeeper might want All Access to Finance and Invoices and Read Only on everything else, so they can answer questions without changing anything.
Give the social manager their own area
Social Media is its own row now, covering connected accounts, posts, the calendar, analytics, the inbox, comments and automations. Someone running your social presence needs that row and very little else, so grant it on its own rather than reaching for a broad preset.
Grant Team carefully
Anyone with Team on All Access can invite, edit and remove other members, including changing your permissions. Most collaborators don't need that. Leave it on No Access unless you're explicitly delegating team management.
Keep Settings tight
Settings covers your workspace name, what kind of business it is, the language it writes in, and the optional features. Mistakes there are annoying to undo. If someone doesn't need to change those, leave Settings on No Access or Read Only. See settings.
Permissions apply immediately
When you save, the new access takes effect right away. Nobody has to sign out and back in. If a member is mid-task when you take something away, they'll bounce on their next click, so tell them first if the timing matters.
Where to go next
- Send an invite with the right preset → inviting team members
- Edit an existing member's access → managing your team
- Adjust the rest of your workspace setup → settings