# Roles & permissions

> What each workspace role can do, and how to choose roles for your team.

_Collection: Workspace, Team & Billing (workspace-admin) — Kepler Help Center. Canonical: https://keplercrm.com/support/articles/roles-permissions/_

Every member has one role, set when they're invited and changeable any time from **Settings → Members** → **Active members**.

## The roles

| Role | Intended for | In short |
| --- | --- | --- |
| Owner | Agency principal | Everything, with no restrictions. |
| Admin | Ops / senior managers | Everything an owner does day-to-day: all records including placement fees, all reports including Placement Finance , workspace settings, and member management. |
| Team lead | Desk / pod leads | Full recruiting access across companies, contacts, candidates, jobs, applications, interviews, lists, activities and tasks. Placements are read-only and fee figures are hidden. Reports yes, finance reports no. Can invite teammates but cannot change roles, remove members or revoke invites, and cannot open workspace settings. |
| Recruiter | Consultants | The 360 desk: full control of companies, contacts, candidates, applications, interviews, lists, activities and tasks, and can create and edit placements — but jobs are read-only , placement fee figures are hidden , and Reports are not available at all. |
| Coordinator | Delivery support | Schedules and runs interviews, moves applications through stages, and manages activities and tasks. Candidates, contacts, companies, lists and placements are read-only; there is no access to Jobs and no Reports. |
| Sourcer | Research / talent pool | Full control of candidates and lists. Companies, contacts, jobs, applications and interviews are read-only; notes and tasks can be created but not edited or deleted; no placements and no Reports. |
| Viewer | Stakeholders | Read-only everywhere, including Reports. Cannot save or change table views. |

Placement **fee and finance figures**, and the **Placement Finance** dashboard, are limited to Owners and Admins. Everyone else sees placements without the money.

## Rules worth knowing

  - **Managing the team:** only owners and admins can change roles, remove members and revoke invitations.

  - **Inviting:** owners, admins and team leads can invite. A team lead can only invite Recruiter, Coordinator, Sourcer and Viewer; an owner or admin can invite any role at or below their own. The invite dialog never offers **Owner** — a second owner is appointed by an existing Owner changing an existing member's role.

  - **Invitations expire after 14 days** and hold a seat until they're accepted, revoked or expired. See [Billing & seats](/support/articles/billing-and-seats/).

  - **Self-protection:** you can't change your own role, you can't assign a role above your own, and the workspace always keeps at least one owner or admin.

  - **Email visibility is orthogonal to roles** — even an owner can't read a teammate's restricted mailbox beyond its sharing level. See [Email privacy & sharing](/support/articles/email-privacy-and-sharing/).

## Choosing roles

Default consultants to **Recruiter** — but if they need Reports, or to create and edit jobs themselves, they need **Team lead** or higher. Reserve Owner/Admin for people who should see fee figures and change workspace settings. Use **Viewer** for anyone who needs to see, not touch.
