Skip to content

Roles

Control what each team member can see and do in graph8 with role-based permissions.

Default Roles

graph8 ships a set of built-in roles tuned to common revenue functions. Each one comes pre-configured with sensible permissions, and you can clone or adjust any of them with custom roles.

RoleDesigned for
AdminFull access to every feature, all data, and all settings (users, roles, billing, integrations).
CROOrg-wide revenue visibility — reads all records and sees every conversation and transcript; limited write for coaching context.
Sales ManagerTeam oversight with full read/write across all records.
SDR ManagerLeads the SDR team — team-scoped read/write on contacts, campaigns, tasks, mailboxes, and phone numbers; can assign leads.
Account Executive (AE)Works an assigned book — reads and edits their own contacts, companies, and deals (including close-won/lost), with broad list visibility.
SDROutbound prospecting — reads and writes their own contacts and lists; hands deals off to an AE.
Commission SDRMarketplace SDR with strict row-level isolation — reads and writes only their own records, no settings access.
CSMOwns existing customer relationships — renewals, expansion, and customer meetings on customer-revenue pipelines.
Campaign ManagerGenerates pipeline through campaigns, forms, and inbound; tracks attribution from their programs.
Support AgentReplies to support conversations — own scope on contacts they touch, team scope on the support inbox, no deals.
FinanceRevenue read-only (all deals and companies for reporting) plus billing, credits, and invoicing.
View OnlyRead-only across team records — cannot create, edit, delete, or change settings. Useful for executives, auditors, and analysts.

The Admin role (and the marketplace Service Provider role) are locked — their permissions can’t be edited, so you always have a guaranteed full-access role.

Permissions

Permissions fall into two groups: per-object scopes (the CRM and engagement objects) and capability toggles (workflows, billing, settings, and team management). Both are configured per role in the role editor grid at Settings → Roles.

Object scopes

For each object below, a role gets an independent View scope and Edit scope, plus optional Delete, Assign, and Manage toggles:

ScopeMeaning
OffNo access to this object
OwnOnly records the user owns or is assigned to
TeamRecords owned by anyone on the user’s team
AllEvery record in the organization
ManageSame as All, and also includes records that have no owner

View and Edit are set separately, so a role can read at one scope and write at a narrower one (for example, View = Team, Edit = Own). Delete, Assign (reassign owners), and Manage are destructive or escalation actions and are flagged Critical in the editor.

The objects with per-row scoping are:

Contacts · Companies · Deals · Campaigns · Lists · Sequences · Tasks · Meetings · Mailboxes · Phone Numbers · Inbox Workspaces · AI Agents

Capability toggles

Non-object permissions are grouped into capability areas:

AreaToggles
WorkflowsView · Run · Manage
BillingView Credits · Purchase Credits · Manage Billing
SettingsAccess Admin · View · Edit
UsersView · Edit Own · Edit All · Invite · Manage
RolesManage Roles
TeamsView · Manage

Access Admin is the master gate for the entire Settings area — a role without it can’t reach any settings page, regardless of the more granular toggles. By default it’s on for Admin, GTM Engineer, and Finance; admins can grant it to other roles on demand.

How scopes affect what users see

A user’s role scope determines which records appear in their lists and detail pages — an Own-scope user sees only their own records, a Team-scope user sees their team’s. graph8 is rolling enforcement out object-by-object, so if a list looks narrower (or a page is hidden) than before, check the user’s role scope for that object in the role editor.

Custom Roles

Create roles tailored to your organization’s structure.

Creating a Custom Role

  1. Go to Settings → Roles
  2. Click Create Role
  3. Name the role and add a description
  4. Set the View/Edit scope and action toggles for each object, plus the capability toggles
  5. Save

Editing a Custom Role

  1. Find the role in the list
  2. Click Edit
  3. Adjust permissions as needed
  4. Save — changes apply immediately to all users with this role

Deleting a Custom Role

  1. Find the role in the list
  2. Click Delete
  3. Reassign users currently on this role to another role
  4. Confirm

Assigning Roles

Roles are assigned when inviting users or from the Users page:

  • On invite — select the role in the invitation dialog
  • After join — change the role from Settings → Users by clicking the role dropdown next to any user

A user can have only one role at a time. Changing roles takes effect immediately.

Frequently Asked Questions

Can I create a role with admin access to just one feature?

Yes. Custom roles let you toggle permissions per feature area. For example, you could create a “Sequence Manager” role with full access to sequences but read-only access to everything else.

What happens when I change someone’s role?

The change takes effect immediately. The user’s current session updates to reflect the new permissions. No logout is required.

Can I duplicate an existing role?

Use the Duplicate option next to any role to create a copy. Rename it and adjust permissions as needed.

Why can’t I grant a permission I don’t have myself?

To prevent privilege escalation, a non-admin can only create, edit, or assign roles that grant permissions they already hold. If you try to give a role a permission you lack, the change is rejected. Organization Owners and Admins are exempt and can grant anything.

Why can’t I edit the Admin role?

The Admin role (and the marketplace Service Provider role) are locked so there’s always a guaranteed full-access role and the marketplace flows keep working. Create a custom role if you need a tailored high-access role.