Roles and permissions
Three workspace roles, one permission matrix, and how per-customer access overrides the defaults.
Three workspace roles, one permission matrix, and how per-customer access overrides the defaults.
Pivotal ships with three workspace-wide roles: Owner, Admin, and Member. A teammate has exactly one role. The role controls what they can change at the workspace level. Access to individual customers, onboardings, and tasks layers on top via the customer record’s Access tab.
“Scoped” means a Member can edit a customer they’ve been granted access to, but can’t create new customers or see ones they weren’t assigned.
Owner is the billing and legal contact. Exactly one per workspace. Use the human who signs the renewal. Transfer it before they leave the company; you can’t transfer ownership of a workspace you no longer have access to.
Admin is your CS leadership tier. Heads of CS, ops, and the implementation lead. Admins do everything except billing-account-level destructive actions. Most workspaces run with two to four Admins.
Member is the working tier. CSMs, AMs, and implementation engineers. They see the customers assigned to them on the Workbench. To widen their view, open the customer record, click Access, and add them. To open every customer to every Member, flip Admin > Workspace settings > Default access to “All Members”.
The customer record’s Access tab overrides workspace defaults in one direction: it can grant a Member visibility to a customer they wouldn’t otherwise see. It cannot demote an Admin or hide a customer from someone who already has workspace-wide visibility. Use it when a Member needs to collaborate on a customer outside their book.
A Member promoted to Admin keeps every customer-level access grant. Demoting back to Member does not strip those grants; the Access tab still lists them. If you need a clean slate, open each customer record and remove the access manually, or email help@pivotal.app to bulk-clear.
Email help@pivotal.app with a screenshot of where you got stuck and the customer or onboarding id from the URL.