# Permissions and roles

> Reply's three-tier role model — organization, team-wide, and workspace roles — with the organization-level permission list, workspace permission categories, and the seat types behind resource access.

**A Reply organization has one permanent owner plus three role levels: Organization roles govern billing, users, and workspaces; Team-wide roles apply one permission set across several workspaces; Workspace roles control sequences, contacts, reports, and other categories inside a single workspace. Approval permissions are clamped so Approve never exceeds View.**

_Status: Reviewed — human-edited, facts not yet confirmed against the product._

An **organization** is available by default for all new Reply accounts. It contains
workspaces (client groups or teams), users, and roles. **Roles** define what actions users
can take; **permissions** determine which features and data they can access. Both are
managed on the Organization page (profile icon → **Organization**), across the Workspaces,
Users, and Roles & Permissions tabs.

## Role levels

| Level | Scope | Use it for |
| --- | --- | --- |
| Organization roles | The entire organization | Billing, inviting and removing users, workspace administration, org-wide objects |
| Team-wide roles | Several workspaces at once | Giving one user identical permissions in all assigned workspaces (account managers, senior SDRs); same permission categories as workspace roles |
| Workspace roles | A single workspace | Access inside one workspace — changes in one workspace do not affect others |

Workspace roles cannot manage organization-level permissions unless the user is also
assigned an Organization role.

## Organization owner

| Rule | Value |
| --- | --- |
| Owners per organization | **One** |
| How assigned | Automatically to the person who creates the account |
| Transfer or removal | Not possible — the role is permanent; only deleting the organization removes it |
| Workspace membership | Automatically part of every workspace; cannot be removed or reassigned |
| Access | All information and any action in the system |

## Default roles

Each organization starts with a Default Team that includes two workspace roles — **Team
Lead** and **Team Member** — in addition to the **Organization Owner**.

| Role | Access |
| --- | --- |
| Organization Owner | Full access to all features, including team creation, role management, and billing |
| Team Lead | Manages team activities and members based on assigned permissions |
| Team Member | Limited access focused on operational tasks within the team |

## Organization-level permissions

Organization roles combine permissions from this list:

| Permission | Grants |
| --- | --- |
| Billing | Manage subscription, update payment methods, view payment history |
| Login as any organization user (except owner) | Sign in as any organization member; the owner's account is excluded |
| Login as any organization user | Sign in as any user, including the owner — full access to all activities and settings |
| Invite new users to Organization | Invite new members to the organization |
| Remove users from Organization | Remove users from the organization |
| Assign roles | Assign organization or workspace roles to users |
| Manage Organization and Team roles and permissions | Create, rename, and edit permission sets for Organization and Team-wide/Workspace roles; grants access to the Roles & Permissions tab on its own |
| Manage Team roles and permissions | The same, scoped to Team-wide and Workspace roles only — cannot create, rename, or edit Organization-level roles; also grants tab access on its own |
| Delete roles | Delete existing organization and workspace roles — required separately; neither manage permission includes delete rights |
| Add users to workspace | Add existing users to specific workspaces |
| Create workspaces | Create new workspaces for clients or teams |
| Edit workspaces | Change workspace names and logos |
| Delete workspaces | Permanently remove workspaces from the organization |
| View workspaces | View all workspaces in the organization, even those the user is not invited to |
| Manage Reply beta features | Enable or disable Reply beta features for the organization |
| Access Organization settings | View and manage organization members and access the Refer & Earn section |
| Access Plans and Billing page | View subscription details and manage plans and billing |

## Organization object permissions

Separate from the list above, organization roles grant access to objects shared across
the whole organization:

| Object | Permissions |
| --- | --- |
| Email templates | View, create, edit, and delete organization-wide email templates |
| Sequence templates | Create, view, and delete organization sequence templates; save AI SDR sequence step structures organization-wide (org-wide structures are read-only for everyone else — usable but not editable or deletable; on by default for existing roles, off for newly created ones) |
| AI SDR playbooks | Create, view, edit, and delete organization-level playbooks for AI SDR sequences |
| Custom fields | Create custom fields; enables publishing a contact field organization-wide |
| Approval Mode (organization) | View Approval Mode queues across all workspaces; take approval actions (approve, bulk approve, regenerate, delete) across all workspaces |

## Workspace permission categories

Workspace roles (and Team-wide roles) combine permissions from these categories:

| Category | Covers |
| --- | --- |
| Sequences | Run, pause, create, delete, archive, and manage sequences; change sequence owners; save sequence step structures to the workspace. The **Manage sequence** permission grants viewing and editing together — there is no separate read-only sequence view permission |
| Contacts | Create, delete, edit, and view contacts |
| Templates | Access, view, use, edit, and delete team templates |
| Reports | View Calls, Email, Workspace Performance, Tasks, LinkedIn, Channel Efficiency, and Agency reports |
| Tasks | View, assign, and complete tasks |
| Accounts | View, create, update, or delete accounts; view or update account settings |
| Integrations | Access Zapier, the Reply API, the Integrations page, and the Reply Marketplace |
| Inbox | Access the Inbox page |
| Data | Access the data search |
| Settings | Access and manage settings from the Team section |
| AI SDR | Access the team's offers, knowledge bases, and playbooks; view and approve messages in Approval Mode with My/Team scopes |
| Website visitors | Create/edit, view, and delete workspace trackers |

Some permissions carry scope options such as **Workspace** and **My** (or **Team** and
**My**) — for example, allowing a user to manage only their own sequences, or to see only
their own approval queue. In Approval Mode, the Approve permission **cannot exceed the
View setting** — the effective level is clamped to the narrower of the two.

To give clients or external partners limited access, create a reports-only role by
enabling only the Reports permission.

## Users and membership rules

- Every invited user must be assigned a workspace and a role; invitations stay *Pending* until accepted.
- A user can belong to more than one workspace, with a different role in each.
- A user can belong to multiple organizations with a single set of credentials; permissions apply independently per organization, and data stays isolated per workspace.
- Users are removed from a workspace via the Workspaces tab, not the Users tab, and only one by one.
- When a user is removed, their contacts, sequences, schedules, unfinished tasks, and templates transfer to the organization owner; their connected email accounts and completed tasks are deleted permanently. This cannot be undone.

## Team Edition

Team Edition adds collaboration inside a team: a unified list of prospects and sequences,
team-level schedules, and a blacklist that works across the team. It runs in **Public** or
**Private** mode depending on how much team members should see of each other's work.

- Once Team Edition is enabled, it cannot be reverted.
- In public mode, only the sequence owner can change a contact's status; any team member can assign the Opted out status — see [Statuses](/reference/statuses).

## Seats

Seats grant access to resources and are separate from role permissions. Each seat type
allows one connected account or feature at a time.

| Seat type | Grants |
| --- | --- |
| Team member | A user who can log into their Reply account |
| Mailbox | An email account connected to send messages; several team members can share one mailbox seat |
| LinkedIn automation | A connected LinkedIn account used for automated LinkedIn steps |
| Cloud calls | Renting a phone number and making calls in sequences |

For accounts with roles and permissions enabled, the billing model sets the seat scope:
with **Organization Billing**, seat limits are shared across the entire organization; with
**Per Workspace Billing**, each workspace gets its own limits independently. Seat counts
per plan: [Limits](/reference/limits).

## FAQ

### Is there a read-only sequence permission?

No. The Manage sequence permission grants access to view and edit sequences owned by the
user or team members — viewing is not split out as a separate permission.

### Can the organization owner role be transferred?

No. Each organization has exactly one owner, assigned automatically at account creation.
The role cannot be transferred or removed; the only way to remove it is to delete the
organization with all its teams and members.

### When should I use a Team-wide role instead of a Workspace role?

Use a Team-wide role when one person needs identical permissions in several workspaces —
edits to the role propagate to every workspace it is assigned in. Use Workspace roles for
one-off access adjustments in a single workspace.

## Related

- [Limits](/reference/limits)
- [Statuses](/reference/statuses)
- [Entity relationships](/reference/entity-relationships)
- [Sequences](/specifications/sequences)
- [Contacts](/specifications/contacts)

## Build with Reply

- REST API: [docs.reply.io](https://docs.reply.io/api-reference/introduction) — authentication and team endpoints
- MCP: [agents.reply.io/mcp](https://agents.reply.io/mcp) — team member and workspace-scoped operations
