Skip to main content
QuivaWorks has seven roles: root, admin, developer, monitor, billing, collaborator and client. Everyone in an account holds exactly one of them, and it decides which parts of the product appear for them. Six of the seven can be assigned to someone: admin, developer, monitor, billing, collaborator and client. Those are the six offered in the Invite dropdown and in the role dropdown on a user.
Root cannot be assigned. It is granted to the person who creates the account, and nothing in the product hands it to anyone else afterwards — not even another root user.
Only root and admin can invite people, change a role, suspend or remove a user.

Role overview

Root

The account creator. Everything, including closing the account.

Admin

Everything root can reach except closing the account.

Developer

Builds and runs things. Secrets and Monitor, no Account or Billing.

Monitor

Sees Monitor and the member list. No Account, Secrets or Billing.

Billing

Billing & Plans only. No Users, no Account.

Collaborator

Works alongside the team. No Flows, Users, Secrets or Gateway.

Client

An external person. Passwordless, scoped to what you grant them.

Root

The role the account is created with. It reaches every surface in the product, and it is the only role that can close the account — Close Account appears in Account → Details for root and for nobody else. Root users are also protected in the Users list: a root row shows its role as fixed text with no dropdown and no dot menu, so a root user cannot be re-roled, suspended or deleted from there.

Admin

Everything root can reach, apart from closing the account. Admins are the working administrators of an account:
  • Invite people, change roles, suspend, unsuspend, log out and delete users
  • View and issue recovery codes for other users
  • Grant a client access to individual resources through Manage Resources
  • Account — details, branding, global assistant instructions and knowledge, escalation responders, data retention
  • Billing & Plans, including emergency credit, budget limits and auto top-up
  • Secrets and Monitor

Developer

Builds and operates. Developers see Secrets, Monitor and Flows. They can also read the member list — the Users item appears for them, with names, email addresses, roles and last login. What they cannot do is write to it: no inviting, no role changes, no suspending, no deleting. Account and Billing & Plans do not appear for them.

Monitor

Sees Monitor and, like developers, can read the full member list without being able to change it. Account, Secrets and Billing & Plans do not appear for the monitor role.

Billing

For whoever looks after payment. The Billing & Plans item appears for root, admin and billing, and from there the billing role can change the plan, buy credit, and set emergency credit, budget limits and auto top-up. Billing does not see the Users item or the Account page.
Billing mail is sent to the root user plus every admin- and billing-role holder. Adding someone to that list is a role assignment, not a support request.

Collaborator

For someone who works alongside your team but should not touch the machinery. Flows, Users, Secrets and the Gateway are all hidden from the collaborator role. Collaborators also cannot see or write internal, staff-only task comments — their comment composer stays on Public.

Client

For someone outside your organisation. The client role is different in kind from the other six:
  • Passwordless. Clients never set a password. They are invited by email with a magic link and a 6-digit code, and sign in through Passwordless Client Sign-In on the login page.
  • Scoped by grant, not by role. A client sees nothing until you give it to them, using Manage Resources on their user — see below.
  • Their own landing page. Clients go to a dedicated client dashboard, and their sidebar has a single item: Home.
  • No seat. Inviting a client does not consume a seat, on any plan.
  • A smaller personal Settings. Advanced Mode, API keys, Calendars, Recordings and Summarization Templates are all hidden for clients.
  • Like collaborators, clients are limited to public task comments.
More about the client experience →

Permission matrix

Rows naming a sidebar item describe what appears in navigation for that role. Where an item sits varies: depending on your account it is at the top level or under More, and some accounts do not surface Flows in the sidebar at all.

Per-user resource grants

Roles are not the only access control. A client user can be given access to named resources one at a time, from Manage Resources in their dot menu on the Users page — available to root and admin. Pick a resource type, tick the individual resources, and set Read, Write and Delete on each, plus Execute where the resource type supports it. Grants cover Spaces, flows, assistants, records, record configurations, files, folders and tasks. This is the mechanism the client role is scoped by: a client with no grants sees nothing.

Changing someone’s role

1

Open Users

Open Users in the sidebar — depending on your account it sits at the top level or under More.
2

Open the person

Click their name in the list.
3

Pick the new role

Choose from the Role dropdown.
4

Apply

Click Update Role.
Changing a role signs that user out of the account. They sign in again and come back with the new role’s access.
A root user’s row has no role dropdown, so root cannot be changed here or anywhere else.

Choosing a role

Give people the least access that lets them do the work, and revisit it when their job changes. Two boundaries are worth planning around deliberately:
  • Reading the member list is not the same as managing it. Developer and monitor can both see everyone’s name, email, role and last login. If that matters to you, those two roles are not “no access to Users”.
  • Collaborator and client are the genuinely narrow roles. For someone outside the team, one of those is almost always the right choice — and a client, unlike every other role, costs you no seat.

User Management

Invite, suspend and remove people

Client Portal

What a client actually sees

Security Overview

Protecting your account

Billing & Subscriptions

Plans, credit and billing contacts