Skip to main content

Teammate permissions: how to control workspace access

Set restrictions on which teammates can access data and features within your Intercom workspace.

Written by Eric Fitzgerald

Sometimes you don't want your entire team to have access to everything within Intercom— that's why we've made it easy to give certain members of your team access to certain data and features in Intercom.

You can edit the permissions of each teammate in the Settings > Workspace > Teammates section of your workspace.

Use this article to understand what each permission controls, edit permissions for individual teammates or in bulk, and manage workspace security. To make changes to a teammate's permissions, you'll need the "Can manage teammates, seats, and permissions" setting enabled on your own account.


What do the permission settings control?

For each teammate you can choose different permissions depending on their needs in the workspace. The table below lists every available Intercom permission, grouped by section, with a description of what each one controls.

Section

Permission

Description

Copilot

Usage

Copilot included usage allows each teammate to use Copilot in up to 10 conversations or tickets per month.

Conversation access

Conversation access

Restrict teammate’s access to conversations according to assignment. Learn more

Note: Conversations a teammate does not have access to will show as redacted, but a teammate will always be able to access conversations assigned directly to them.

Settings

Can manage general and security settings

Without this, teammates cannot access some of the General settings, create Custom Objects and all of the Security settings.

This includes the following settings:

General settings

Security settings

Can manage teammates, seats and permissions

Without this, teammates cannot access the Teammates section in Workspace settings, including Roles and Activity logs.

This includes the following settings:

  • Allows teammates to add or remove teammates

  • Edit teammate permissions

  • Change Away and Reassignment for teammates

  • Edit teammate role-based permissions

Can edit own profile

Controls who can edit their own public profile and avatar.

Can edit other teammates' profiles

Controls who can edit other teammate’s public profile and avatar.

Can manage teams

Without this, teammates cannot access the Teams section in Inbox settings.

Can change status

Without this, teammates cannot edit other teammate's away status

Can access Messenger settings

Without this, teammates cannot access the Messenger section in the Channels settings.

This includes the following settings:

  • Edit Messenger intro and localisation

  • Enable/disable "Reply expectations" feature to show reply times during office hours (Note: "Can manage workspace data" and "Can manage Messenger settings" permissions will be needed to actually set office hours)

  • Add Messenger Home apps

  • Style your Messenger

  • Control inbound and outbound conversations (eg: who can see your Messenger)

  • Security settings for Messenger (allowlisting domains, identity verification)

Can manage Billing settings

Without this, teammates cannot access the Billing section of a workspace and cannot delete a workspace.

This includes the following settings:

  • Change subscription (products)

  • Edit credit card details

  • Edit billing contact and address

  • Access and download invoices

  • View Fin outcomes in Billing

Can manage usage alerts

Without this, teammates cannot modify the usage reminder section of a workspace.

This includes the following settings:

  • Editing Usage Reminders

Can manage hard limits

Without this, teammates cannot modify the usage limit section of a workspace.

This includes the following settings:

  • Editing Usage Limits

Can access Proactive Support settings

Without this, teammates cannot access Proactive Support settings.

This includes the following settings:

  • Subscriptions

  • Newsfeeds

  • News Labels

  • Customization

Note: This permission is independent of the Proactive Support Plus add-on. It can be enabled or disabled regardless of which add-ons are active on the workspace.

Can edit Default sender address

Without this, teammates cannot edit the default sender address within Email settings.

Data and security

Can access workspace data

Without this, teammates cannot access Data settings, including:

  • Tags

  • People

  • Audiences

  • Companies

  • Conversations

  • Custom Objects

  • Imports & exports

  • Add or edit office hours for workspace

  • Add or edit team-level (custom) office hours for workspace

  • Access the brand selector when Multibrand is enabled

Can access people, companies, and account lists

Without this, teammates cannot access workspace Contacts, restricting access to users, leads, companies, accounts, and conversations.


Note: Some of this data can still be accessed in other product areas (e.g. Proactive Support, Reporting).

Can access lead and user profiles

Without this, teammates cannot access individual lead, user, or company profiles. They will either be blocked from moving off their current screen (Inbox or Contacts) or redirected to their inbox if they arrive from a URL link.

Can export lead, user, company data

Without this, teammates cannot export people or company data from the Contacts List, they also cannot export most Reporting comma-separated values (CSV) files.

Can import contacts, companies and tickets

Without this, teammates cannot import new data via CSV from Contacts, or via Mixpanel or Mailchimp apps, or from Zendesk.

Can manage tags

Without this, teammates cannot create new tags via the Inbox, or from Tags settings.

Note: They can still tag conversations.

Can view all teammate and team details

Without this, teammates cannot see the personally identifiable information (PII) of teams they are not part of, or of teammates they do not share a team with. Those teams and teammates will be shown as “Redacted”.

Note: The ability to tag lite users also requires this permission. This permission is also required to reassign conversations to team inboxes you're not a member of. Without it, the option to select other team inboxes will be limited, even if other permissions are enabled.

Apps and integrations

Can access developer hub

Without this, teammates cannot access Developer Hub in the workspace.

Can install, configure and delete apps

Without this, teammates can visit the app store but must request an app be installed from an admin in a dropdown list.

Can trigger data connector actions

Controls the ability to run data connectors manually within the Inbox.

Knowledge

Can create and manage content in Knowledge

Without this, teammates can view content in Knowledge, but cannot create, import, or update content.

Can create and update draft Help Center articles

Without this, teammates can view public articles in Knowledge, but cannot create or or save changes to any public articles.

Note: Teammates with this permission can only save draft versions, they can't publish them live to a Help Center.

Can manage and publish Help Center articles

Without this, teammates cannot publish or unpublish Help Center articles, set the Help Center live, or manage Help Center settings and collections.

Automation

Can manage Automation settings and inbound Workflows

Without this, teammates cannot create, edit, delete, duplicate, set live, or pause inbound workflows, nor can they change automation settings. They also cannot make changes to Fin Guidance. However, they can still tag existing workflows.

Can manage outbound Workflows

Without this, teammates cannot create, edit, delete, duplicate, set live, or pause outbound workflows. However, they can still tag existing workflows.

Can view Fin and Automation settings

Without this, teammates cannot access the Fin AI Agent tab, which includes:

  • Fin AI Agent

  • Workflows

  • Simple automations

Note: This still gives teammates permission to create/update resources like Batch Test questions and Simulations.

Proactive Support

Can bulk message visitors, leads and users

Without this, teammates cannot set any content-type live from Proactive Support, but they can still reach out individually from Contacts.

Note: Setting any Outbound Workflows live also requires the "Can manage Outbound Workflows" permission.

Can publish News

Without this, teammates can create and edit News Items but they cannot set any items live.

Can send outbound emails from custom email addresses

Without this, teammates can neither create an email template in Proactive Support with a custom address sender, nor start a conversation via the Inbox composer (Inbox > New conversation) from a custom address.

Can export Proactive Support data

Without this, teammates cannot export audiences or content performance in Proactive Support.

Has to use default rules in new messages (only available in Custom Roles)

Without this, teammates can set any audience filters for any content type.


Does not apply to 1:1 messages/chats.

Note: This can only be set up in Custom Roles, not for individual teammates.

Can set Product Tours, Tooltips, and Checklists live

Without this, teammates cannot set a product tour live for end users.

They can still create and save product tours as drafts, and edit existing product tours.

Can set Surveys live

Without this, teammates cannot set a survey live.

They can still create and save surveys as drafts, and edit existing product tours.

Can manage Surveys data

Without this, teammates cannot view the Survey Responded stats, or the Survey Responses report, or export Survey data as a CSV.

Inbox

Can access real-time dashboard

Without this, teammates cannot access the Inbox dashboard.

Can reassign conversations and edit lead or user ownership

Without this, teammates cannot reassign conversations from another teammates' inbox, or edit lead ownership via the sidebar or profile.

Note: They can still reassign conversations from their own inbox, the unassigned, and other team inboxes.

Can reassign conversations when going away

Control who can set their status to "Away and reassign". This only applies when reassigning someone else’s conversation.

Can assign conversations to themselves

Without this, teammates cannot assign a conversation to themselves (including via the Inbox assignee picker, Command-K, as a side effect of replying, bulk assignment, macros, or the REST API). Automated routing, workflows, and round-robin or load-balanced assignment are unaffected.

Can remove themselves as the assignee of a conversation

Without this, teammates cannot unassign themselves from a conversation. Automated routing and assignment are unaffected.

Can create conversations

Controls the creation of new conversations, tickets, and phone calls. Without this, teammates cannot use the "Create new" menu to start any new items in the Inbox.

Can manage conversation participants

Controls who can add or remove participants on conversations. Without this permission, teammates cannot add new people to a conversation or remove existing participants.

Can merge conversations

Controls the ability to merge conversations. Without this, the option to merge conversations will not be available to the teammate.

Can delete replies from a conversation

Without this, teammates cannot delete replies from any conversation they can access.

Can delete notes from a conversation

Without this, teammates cannot delete internal notes from any conversation they can access.

Can change ticket type

Without this, teammates cannot change the ticket type of an existing ticket using the ticket type dropdown in the ticket sidebar.

Can export conversation transcripts

Without this, teammates cannot export the conversation transcript from the Inbox as a .txt file.

Can edit notes

Without this, teammates cannot edit notes on conversations or tickets they can access.

Can manage views

Without this, teammates can view existing Inbox views but not create new views or edit existing ones.

Can enable undo send delay

Controls whether the undo send delay option appears in the Inbox composer. Without this permission, teammates won't see the undo send delay option when sending messages. When enabled, teammates can choose a delay of 5s, 10s, 20s, or 30s — a visual Undo option shows on screen. Works in direct messages, channels, and threads.

Workload Management

Can manage rules

Without this, teammates cannot access the Settings > Inbox > Rules

Can manage Balanced assignment and Workload management

Without this, teammates cannot access Workload management in Inbox Assignments settings, nor select the Balanced assignment method when editing Teams settings.

This permission also controls editing the team reply time setting and managing office hours for individual team inboxes. Without it, the option will be greyed out.

Can manage Round Robin assignment

Without this, teammates cannot select the Round Robin assignment method when editing Teams in settings.

Can manage auto away mode

Without this, teammates cannot access the Automatic away mode configuration in Inbox settings. More info

Can manage teammate presence

Without this, teammates cannot access the Teammate presence configuration in Inbox settings that controls whether the Inbox displays any additional teammates are viewing a conversation at a given moment.

Phone

Can listen on calls

Without this, teammates cannot monitor live calls, coach teammates privately (Whisper), or join calls as an active participant (Barge).

Can delete call recordings

Without this, teammates cannot delete call recordings.

Macros

Can manage shared macros

Without this, teammates can only create macros for their own personal use in Settings > Inbox > Macros (they will not be available to other teammates).

Can create macros

Controls who can create shared macros that are available for other teammates to use.

Can edit macros

Controls who can edit shared macros.

Can delete macros

Controls who can delete shared macros.

Can use personal macros

Controls the ability to create and use personal macros within the Inbox.

Reports

Can access Reports

Without this, teammates cannot access workspace Reports including outbound reporting.

Can share Reports

Without this, teammates cannot export conversation or ticket data from the Data export section in Reports.


Note: "Can access Reports" permission is required to access this feature.

Can export CSV

Without this, teammates cannot export conversation data from the Data export section in Reports.

Note: "Can access Reports" permission is required to access this feature.

Can access Chart drill-in

Without this, teammates cannot access drill-in data from Custom reports.

Can manage Workspace folders

Without this, teammates cannot control which folders and reports are visible in other teammates' individual workspaces.

Can view/edit/delete Custom reports

Without one of these, teammates have gradually increasing access to custom reports, ranging from; no access at all, view only access, view and edit existing reports and charts, or all of the above plus deletion permission.

Note:

  • Teammates without any Proactive Support permissions will still be able to access Proactive Support in the workspace but won't be able to set content live.

  • In order to add apps to Messenger Home teammates need "Can manage workspace data and workload management" as well as "Can access Messenger settings".

  • Test workspaces inherit teammates and permissions from the main workspace. To add new teammates or update permissions, switch to the main workspace.


How to edit permissions

Can I edit my own permissions?

You cannot manage your own permissions or edit your own permissions access. This is a security measure to ensure every workspace has at least one teammate with admin permissions.

If you need your own permissions changed, ask a teammate who has the "Can manage teammates, seats, and permissions" permission to update them for you.

We recommend keeping at least two teammates with full permissions to ensure continuity and security.

How do I edit another teammate's permissions?

From Settings > Workspace > Teammates, simply click on the teammate's name you want to update, then select their individual permissions and click Save changes.

Screenshot of Settings > Workspace > Teammates showing a teammate row with the Edit button highlighted on hover.

  1. Navigate to Settings > Workspace > Teammates in Intercom.

  2. Locate the teammate's account and hover over their name.

  3. Click Edit and toggle the specific permissions on or off as needed.

  4. Review and confirm changes.

  5. Changes will be logged and visible in the workspace in the Teammate Activity Logs.

  6. Permission changes take effect immediately after saving — the teammate does not need to log out and back in. The change is recorded in Teammate Activity Logs.

When assigning admin-level permissions, ensure the following permissions are enabled:

  • "Can manage general and security settings"

  • "Can manage teammates, seats, and permissions"

How do I edit permissions for multiple teammates at once?

To edit the permissions for multiple teammates, hover over their profile picture and check the box that appears. Then click Edit permissions.

Screenshot of the Teammates list with multiple teammates selected via checkbox and the Edit permissions button highlighted.

Choose the permissions for the selected teammates — the same options available when editing an individual teammate — then click Save changes.

Permission changes take effect immediately for all selected teammates — no log out required. All changes are recorded in Teammate Activity Logs.

The teammates selected will be listed at the top of the page throughout this process, as shown in the screenshot.

Screenshot of the bulk permissions editor showing selected teammates listed at the top of the page above the permissions toggles.

Tip: If you're setting custom permissions, review the Teammate Activity Logs to detect unexpected behavior like configuration changes or data exports. See Review actions taken in your workspace with Teammate activity logs.

Every workspace also includes a system operator account (e.g. operator+{workspace-code}@intercom.io) used for automated actions like deprovisioning teammates. To audit its activity, go to Settings > Teammate Activity Logs and filter by the operator account.

What to do if admin access is lost

If no admin exists in the workspace: Add a new teammate in Settings > Workspace > Teammates, assign them the "Can manage teammates, seats, and permissions" permission, and have them restore your access.

If no one has complete access: A teammate with permission to manage teammates must go to Settings > Workspace > Teammates, select a teammate to edit, enable all permissions, and save the changes to grant full access.


💡Tip

Need more help? Get support from our Community Forum
Find answers and get help from Intercom Support and Community Experts


Did this answer your question?