Invite teammates and set their roles
Four roles decide who can edit a live flow, who can see the values a run moved, and who can touch the card on file. Here is what each one covers and how to change it.
<h2>What a role controls</h2><p>A Syncline workspace has four roles. They decide who can change a running flow, who can read the values a run carried between apps, and who can see the billing page. Roles are set per workspace, so the same person can be an admin in your main workspace and a viewer in a client one.</p><table><thead><tr><th>Role</th><th>Build and edit flows</th><th>See run values</th><th>Manage connections</th><th>Billing</th></tr></thead><tbody><tr><td>Owner</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Admin</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Read only</td></tr><tr><td>Builder</td><td>Yes</td><td>Own flows only</td><td>Use, not add</td><td>No</td></tr><tr><td>Viewer</td><td>No</td><td>Masked</td><td>No</td><td>No</td></tr></tbody></table><p>Every workspace has exactly one owner, and the owner is the only person who can transfer that role to somebody else. If the owner leaves the company, an admin can request a transfer from support with a note from a second admin on the account.</p><h2>Invite someone</h2><ol><li><strong>Open Settings, then People.</strong> The list shows everyone with access, their role and the date they last signed in.</li><li><strong>Click Invite.</strong> Type the work email address. Personal addresses work, but the audit log reads better when the domain matches your company.</li><li><strong>Choose a role.</strong> Builder is the right default for anyone who will actually make flows. Viewer suits a manager who wants the dashboard and nothing else.</li><li><strong>Restrict connections if you need to.</strong> A builder can be limited to a named set of connections, which is how agencies keep one client's accounts out of another client's flows.</li><li><strong>Send the invitation.</strong> The person gets an email with a link that signs them straight into your workspace.</li></ol><blockquote><p>Note: an invitation link expires after seven days. If somebody was on holiday when you sent it, open the People list and click <em>Resend</em> rather than creating a second invitation, which leaves two pending rows for the same address.</p></blockquote><h3>What a viewer actually sees</h3><p>A viewer opens the dashboard, the flow list and the run history, and sees that a run succeeded or failed and how long it took. The record values inside each run are masked, so a viewer can tell you that eleven contacts moved this morning without being able to read the eleven email addresses. Support teams usually give a manager this role and nothing more.</p><h2>Changing or removing access</h2><p>Change a role from the same People list and it takes effect on the person's next page load. Removing somebody is immediate: their session ends, their invitation links stop working, and any flow they built keeps running under the workspace rather than under them.</p><p>The one thing removal does not do is delete their connections. If a departing colleague authorised the Gmail account a flow depends on, that connection keeps working until the mailbox itself is closed. Reconnect it under an account that will still exist next quarter, ideally a shared address rather than a person.</p>