Skip to main content

What are Roles & Permissions?

Every person on a Voxworks team holds a role, and every role sits at a rank in a hierarchy. Your rank decides two things: which capabilities you’re granted, and which teammates you’re allowed to manage. Every team starts with two roles available — Owner and Member — and one member is always flagged as the team’s primary owner, a special status layered on top of a role rather than a role itself. You can see everyone’s role on Settings → Members, in the Role column. Any management action you’re allowed to take on a teammate — updating their role, transferring ownership, or removing them — is reached from that row’s actions menu (the icon). This page explains the model behind those permissions; for the click-by-click mechanics of inviting, changing roles and removing people, see Inviting & Managing Members.

The role hierarchy

Voxworks ranks roles from most to least senior: Owner outranks Member. An intermediate Admin rank, sitting between the two, is also recognised by the permission system — Voxworks can configure it for a team on request, though it isn’t something you create yourself from Settings. Rank governs who can act on whom:
  • You can only change the role of, or remove, a teammate ranked below you.
  • Two people holding the same role can’t manage each other — not even two Owners. Only the primary owner can act on a fellow Owner.
  • Attempting to manage a peer or a more senior teammate returns the error “You do not have permission to action a member from this account”.
Whoever sends an invitation picks the invitee’s role from a dropdown, and can only offer roles at or below their own rank — an Owner can invite someone as Owner or Member, while a Member can only invite new people as Member. See Inviting Members for the full invite flow.

The primary owner

Every team has exactly one primary owner — the account’s original creator, or whoever ownership has since been transferred to. The Members table marks this person with a yellow Primary Owner badge next to their role badge. It’s not a separate role; it’s a single flag layered on top of whichever role (normally Owner) that person holds. The primary owner:
  • Always has every permission, regardless of what their assigned role would otherwise grant.
  • Can never be removed from the team. Their row in the Members table has no actions menu at all.
  • Can’t leave the team from the Danger Zone — they must transfer ownership to someone else first.
  • Is the only person who can rename the team, change its phone number, or delete it outright. This check is independent of role, so even a fellow Owner who isn’t the primary owner is blocked, with: “Only the team owner can update these settings. Please contact your team owner to request changes.”

Transferring ownership

Because handing over the primary owner flag is high-impact, moving it — via Transfer Ownership on a member’s row — is gated behind a one-time verification code sent to your email, the same pattern used for other destructive account actions (see Multi-Factor Authentication). Only the current primary owner can start a transfer this way; the full steps are on Inviting & Managing Members. Inviting someone with the Owner role only grants them the Owner role once they accept — it does not make them the primary owner. Primary ownership only ever moves through Transfer Ownership.

What each permission unlocks

Five capabilities gate every role-sensitive action on a Voxworks team. A Member holds two of them by default; an Owner (and the primary owner, always) holds all five. This split explains a few things you’ll notice in the UI: a Member sees the Invite Members button, but the update-role and remove options never appear on their row menus in the Members table; and a Member can send a brand-new invite but can’t edit, renew, or delete one that’s already pending — only an Owner can. An Admin role, where one is configured for your team, sits between these two columns; Voxworks tailors exactly which capabilities it carries when setting it up. Errors you’ll see when one of these is missing:
  • “You do not have permission to action a member from this account” — updating a role or removing someone without the roles/members capability, or targeting someone ranked at or above you.
  • “You do not have permission to manage routing” — editing Numbers & Routing without the settings capability.
  • “You do not have permission to delete flows” — deleting a flow in the script editor without the settings capability.
  • “Only the team owner can update these settings. Please contact your team owner to request changes.” — editing the team name or phone number as anyone other than the primary owner.

Next Steps