Assign roles by responsibility
The cleanest permission model is responsibility-based. People should have enough access to do their job, but not broad access just because it is convenient in the moment.
- Finance owners need billing and payment context.
- Sales operators need leads, proposals, and client context.
- Delivery teams need projects, messages, and deliverables.
- Only a small set of users should manage workspace-wide settings and connected integrations.
Admin hygiene checklist
- Review roles quarterly
- Remove old access quickly
- Watch connected app grants
- Keep billing and payout owners explicit
