RBAC in practice — what owner, admin, manager, and member actually do
A practical guide to the four roles in a Leadline workspace — what each one can see, what each one can change, and how to set up a workspace for a team of 3, 10, or 30.

A Leadline workspace has four roles: owner, admin, manager, member. The roles are not abstract permission grants; they are designed to map to the way real teams work.
This is the practical guide for what each role does, who should be which, and how to set up a workspace for the kind of team you have.
The four roles, in plain English
Owner — the person who created the workspace and the credit card on it. There is exactly one owner per workspace. The owner can do everything: invite, remove, change roles, change billing, delete the workspace. The owner cannot be removed (they would have to transfer ownership first).
Admin — the person who runs the day-to-day. Admins can invite and remove people, change roles for everyone except the owner, edit workspace settings, see all leads, see all calls. Admins cannot change billing (that’s the owner). Most agencies have one or two admins.
Manager — the person who runs a pod. Managers see the leads assigned to the team they manage, plus their team’s calls. They can change stages on leads in their team, write notes, dial from the queue, save views. Managers cannot see other teams’ leads, cannot invite or remove people, cannot change billing. Most agencies have one manager per team (per client, per region, per vertical — depends on the agency).
Member — the person who does the work. Members see only their own leads. They can dial from the queue, write notes, change stages on their own leads. Members cannot see other members’ leads, cannot invite or remove people, cannot change billing. This is the SDR / researcher / operator role.
What each role sees
The visibility rule is simple: you see the leads you own plus the leads in any team you manage plus (for admin/owner) the entire workspace.
Concretely:
| Role | Sees own leads | Sees team leads | Sees all workspace leads |
|---|---|---|---|
| Owner | yes | yes | yes |
| Admin | yes | yes | yes |
| Manager | yes | yes (their team only) | no |
| Member | yes | no | no |
The “team” abstraction is what makes the difference. A workspace has one or more teams. Managers are assigned to one or more teams. Members are assigned to one or more teams. The workspace owner / admin can see all teams; everyone else sees only their own.
What each role can change
| Action | Owner | Admin | Manager | Member |
|---|---|---|---|---|
| Place a call | yes | yes | yes | yes |
| Save a row | yes | yes | yes | yes |
| Change stage on own lead | yes | yes | yes | yes |
| Change stage on team’s leads | yes | yes | yes | no |
| Change stage on any lead | yes | yes | no | no |
| Save a view | yes | yes | yes | yes |
| Edit workspace name | yes | yes | no | no |
| Invite a person | yes | yes | no | no |
| Change a role | yes | yes | no | no |
| Remove a person | yes | yes | no | no |
| Change billing | yes | no | no | no |
| Delete the workspace | yes | no | no | no |
The pattern: anything that changes the team’s structure is admin/owner. Anything that changes a single lead is the lead’s owner or someone in the same team.
A workspace for an agency with one client
If you’re a solo operator who occasionally brings in a partner:
- One team called “Default” or “All leads”.
- You = owner.
- Partner = admin (so they can invite others if you bring in more people, and so they can edit workspace settings).
If your partner dials too, they can be a member instead of an admin — same lead visibility, just no workspace-level permissions. The role choice is about who can change the workspace, not who can use it.
A workspace for an agency with many clients
If you’re an agency running outbound for 12 clients:
- One team per client (“Acme”, “Beta”, “Gamma”, etc.).
- Owner = the agency’s account director (you).
- Admins = the operations manager.
- Managers = one per client team. The person who runs the Acme pod is a manager assigned to the Acme team.
- Members = the SDRs. Each SDR is a member assigned to one or more client teams.
The SDR sees only their own leads. The manager for Acme sees the Acme team’s leads (across all SDRs). The admin sees all teams. The owner sees all teams and can change billing.
If a client leaves, the agency deletes the team. The leads and recordings for that client go with the team. The other clients’ work is untouched.
A workspace for an in-house SDR team
If you’re running a sales team inside a single company:
- One team per region (“EMEA”, “AMER”, “APAC”) or per segment (“SMB”, “Mid-market”, “Enterprise”).
- Owner = the VP of Sales.
- Admins = the sales operations manager.
- Managers = the regional sales managers. Each manager sees their region’s leads.
- Members = the SDRs.
Same shape as the agency, but the team boundaries map to the company’s org chart instead of client accounts.
A workspace for a solo operator
If you’re one person:
- One workspace, one team, one owner.
- You are also the admin (owner automatically has admin permissions).
- That’s it.
The roles only matter when there are more than one person. If you’re solo, the role structure is mostly latent — it activates the moment you invite your first team-mate.
Common mistakes
A few things teams get wrong:
- Making everyone an admin. Admins can see every lead, change every stage, invite and remove. Most reps shouldn’t have that. Members is the right default; promote to manager when someone needs to see a team’s leads, promote to admin when someone needs to manage the workspace.
- No teams. A workspace with no teams treats every member as a single-team workspace. If you have 10 SDRs and no teams, every SDR sees their own leads (good) but no one can see a team’s aggregate (bad — your manager has nothing to look at). Make at least one team.
- One team per person. A workspace with 10 SDRs and 10 teams is the same as no teams — every manager sees only their own member’s leads, and there’s no aggregation. Make a team per role (SMB, Mid-market, etc.) and assign multiple members to it.
- Owner leaves the company. The owner cannot be removed, but they can transfer ownership. If the owner leaves, transfer first, then remove.
Where to go next
If you have a Team workspace, open Settings → Members and look at who has which role. Adjust if needed.
If you’re starting a new Team workspace, decide your team boundaries first (per client, per region, per segment — whatever matches your org). Then assign managers to teams, members to teams, and you’re set.
If you want to read more:
- Solo vs Team — for the broader question of whether to upgrade from Solo at all.
- The dialer — for the workflow that the RBAC protects.
- What we don’t do — for the boundaries.
The roles are not the product. The roles are how the product stays safe to share with more than one person.