Give every teammate exactly the access they need — and nothing they don't.
Start from six role presets, then flip individual capabilities until access matches how your team actually works. Every change lands in the workspace audit log, and every client workspace stays walled off from the next.
Sam Rivera
teammate · acme-social
Inbox
Read & reply to conversations
Contacts
Audience, tags & notes
Flows
The automation canvas
Broadcasts
Bulk sends & campaigns
Billing
Plan, invoices & card
Admin
Workspace & account settings
Pick a preset or flip a switch — every change lands here.
Pick a role preset to snap the matrix into place — then flip any switch and watch the audit log record it.
What is Team, Roles & Permissions?
Team, roles, and permissions control who on your team can see and do what inside a shared social-media inbox. In KlyoChat you invite a teammate to a workspace, start them from one of six role presets — Full access, Team lead, Community manager, Automation manager, Inbox agent, or Viewer — then toggle six independent capabilities (Inbox, Contacts, Flows, Broadcasts, Billing, Admin) between none, view, and manage until access matches the job. Everyone signs in with their own login, each client workspace stays walled off from the next, and every invite and permission change is timestamped in a per-workspace audit log.
6 presets
One-click defaults, from Full access to Viewer
6 capabilities
Inbox, Contacts, Flows, Broadcasts, Billing & Admin — toggled independently
1 audit log
Every invite and permission change, per workspace
What Team, Roles & Permissions changes
70%
faster first response with more agents on the inbox
<2 min
to onboard an agent with exactly the right access
0
shared passwords — everyone signs in with their own login
100%
of invites and permission changes captured in the audit log
From invite to exactly the right access
Every preset is a plain map of capabilities to access levels — none, view, or manage. Start from a preset, override any key, and KlyoChat writes the diff to the workspace audit log.
Invite by email or link
Send a personal email invite or drop a shareable workspace link in your team chat. You set the workspace and starting role before anyone arrives, so nobody logs in with more reach than you intended.
Start from a role preset
Pick one of six presets — Full access, Team lead, Community manager, Automation manager, Inbox agent, or Viewer — to set sensible defaults across every capability in a single click.
Fine-tune the capabilities
Flip individual switches: let a VA manage the inbox but never see billing, or give a strategist Flows without Admin. The preset relabels to Custom the moment you deviate.
Trust the audit log
Every invite, role change, and capability edit is timestamped in the workspace audit log — who did it, what changed, from what to what — so you always know who changed what.
{ "role": "inbox_agent", "workspace": "acme-social", "capabilities": { "inbox": "manage", "contacts": "view", "flows": "none", "broadcasts": "none", "billing": "none", "admin": "none" }, "overrides": { "contacts": "manage" }}Everything in Team, Roles & Permissions
Presets to start, a matrix to finish
On fixed-tier tools you pick Admin or Agent and live with whatever that tier decided. In KlyoChat, the six presets are just starting points — every capability (Inbox, Contacts, Flows, Broadcasts, Billing, Admin) is its own switch. Give someone the inbox without the billing tab, or automations without admin, with no “upgrade to Enterprise for custom roles.”
One login, many client workspaces
Multi-tenant workspaces keep every brand or client walled off. Switch between them from the workspace switcher without logging out, and a teammate's access in one workspace never leaks into the next. An account manager can oversee several brands; a freelancer sees only the one you invited them to.
An audit log that settles arguments
Every invite, role change, and capability edit is timestamped — who did it, what changed, from what to what. When a client says they never approved something, or a broadcast went out that shouldn't have, you can trace exactly where it happened instead of guessing.
Invite by email or link — with a role attached
Send a personal email invite or drop a shareable link in your team chat. Either way you set the workspace and starting role before they arrive, so nobody logs in with more reach than you intended. New agents land ready to work in the inbox, not staring at your automation canvas.
Least privilege without the spreadsheet
The safest default is only what this person needs. Start a VA from Inbox agent, a strategist from Automation manager, a stakeholder from Viewer — then tighten or loosen a single capability. Everyone uses their own login, so you retire access by removing one person, never by rotating a shared password.
Billing and admin stay yours
Handing off the inbox shouldn't mean handing over the credit card. Billing and Admin are their own capabilities, off by default on every preset except Full access and Team lead — so you can grow the team that touches conversations without widening the circle that touches money or account settings.
One feature, every platform you're on
New channels arrive as adapters, not rewrites — so this works the same wherever your customers message you.
Pairs well with
Unified Inbox
Every channel in one calm feed.
Assign, snooze, tag, and resolve conversations from every channel without switching tabs.
Learn moreAnalytics & Reporting
See what's working — and who's carrying the load.
Account performance, broadcast funnels, and per-agent response metrics in one view.
Learn moreContacts & CRM
A CRM that speaks DM.
One contact record merged across every channel, with custom fields and dynamic segments.
Learn moreCommon questions
Ready to run every conversation from one calm inbox?
Start your free trial. No credit card. Connect your first channel in under a minute.