Roles & permissions
A role is a named set of permissions you can assign to members of your community. Instead of giving someone full admin access, you create a role (e.g. "Moderators", "Event team", "Finance") with exactly the permissions they need and assign members to it. A member can hold more than one role; their effective access is the union.
Manage roles in the admin app under Settings → Roles.
The Founder role
Every community is created with a system Founder role that holds every permission, and the creator is its first member. The Founder role:
- cannot be deleted,
- is capped at 2 members (the owner plus one co-founder), and
- can only be assigned by an existing founder.
Permission catalog
What each permission lets a role do:
Content
| Permission | Lets the role… |
|---|---|
| Manage channels | Create, edit, and delete feed channels |
| Moderate feed | Remove or pin any member's post (not just their own) |
| Pin posts | Pin and unpin posts in the feed |
| Post announcements | Post in the announcements channel |
Members
| Permission | Lets the role… |
|---|---|
| Review requests | Approve or decline membership applications |
| Invite members | Send invitations |
| Generate invite URL | Create shareable invite links |
| Kick members | Remove members |
| Ban members | Permanently ban members |
Events & marketplace
| Permission | Lets the role… |
|---|---|
| Create events / products | List new events or products |
| Manage event / marketplace listings | Edit and remove listings |
Community
| Permission | Lets the role… |
|---|---|
| Branding | Manage branding and appearance |
| Onboarding form | Configure the membership application form |
| Prerequisites | Set membership prerequisites |
| Rules | Manage community rules |
| Atlas | Manage Atlas categories |
Sensitive — founder-only to grant
| Permission | Lets the role… |
|---|---|
| Payouts | View and manage community finances |
| Manage roles | Create roles and assign permissions |
| Access admin app | Log in to the admin dashboard |
Rules that protect owner-level access
A few guardrails keep delegated role management from becoming a backdoor to owner control:
- Sensitive permissions are founder-only to grant. A member with Manage roles can build and assign roles, but cannot grant Payouts, Manage roles, or Access admin app unless they are a founder — so a role admin can't escalate their own access.
- No self-assignment. You can't change your own roles; a second person with Manage roles (or a founder) does it.
- Founder is protected. Only a founder can add someone to the Founder role, and the 2-founder cap holds everywhere — direct assignment, invitations, and automations alike.
- Member post deletion is owner-scoped. Every member can delete their own posts; deleting another member's post requires Moderate feed.
Who can see member contact info
Roles also gate access to member data. A member's email and application-form answers are visible to leaders holding Review requests (and similar member-management permissions) — never to other members, and never on public profiles. See Auth & page access.