Workspace & Catalogs

Roles and permissions overview

Invite people securely and understand the access provided by each Workspace role.

6 min read
6 min read
Last reviewed 2026-08-13
Last reviewed 2026-08-13
Beginner
Beginner

Overview

Workspace roles govern access inside one organization. Members settings supports four customer roles: Owner, Admin, Editor, and Viewer. Platform roles such as Platform Super Admin are separate and can never be granted through Workspace membership.

Owner can manage Workspace configuration, members, billing, catalog editing, ingestion, and exports. Admin can manage Workspace configuration and members, edit catalogs, run ingestion, and run exports, but cannot change or remove the Owner. Editor can edit catalog metadata but cannot manage members, run exports, or run ingestion. Viewer has read-only Workspace access and cannot elevate their own permissions.

Before you begin

Open the correct Workspace and use the least-privileged role that supports the person's work. Owner and Admin can invite any email address. The recipient can sign in to an existing account or create a free CatalogIQOS identity during acceptance. Joining the inviting Workspace does not require a separate subscription purchase.

Where to find it

Open Workspace → Members at /settings/members. Workspace switching and ownership context are under /settings/workspaces.

Step-by-step instructions

  1. Open Settings, then Members & Roles, and confirm the active Workspace.
  2. Enter the recipient's email and choose Admin, Editor, or Viewer. Owner cannot be assigned or transferred here.
  3. Select Send Invitation. CatalogIQOS emails a secure, single-use acceptance link that expires after seven days.
  4. The recipient follows the link and signs in with the invited email, or creates a free identity for that email.
  5. CatalogIQOS creates Workspace membership only after successful acceptance.
  6. Use Resend to invalidate the previous link and issue a new seven-day link, or Revoke to prevent acceptance.

What happens next

After acceptance, the account can open the Workspace with the assigned role. Invitations and memberships are scoped to the active Workspace. Duplicate active invitations and duplicate memberships are rejected. The invitation cannot be accepted from a different email account.

Best practices

Add individuals separately, review membership regularly, and remove access when responsibilities end. Use Viewer for inspection and Editor only when catalog metadata changes are required. Reserve Admin for people trusted to manage other members and Workspace settings.

Common problems

An expired, revoked, or already-used link cannot create another membership. Ask an Owner or Admin to resend an expired invitation. A duplicate member must be managed from its existing row. Owners cannot remove or demote themselves, Admin cannot change the Owner, and no member can grant a platform role through this page.

Troubleshooting

Confirm the active Workspace, exact invited email, and displayed role. If the signed-in email differs from the invitation email, sign out and use the invited account. Older rows labeled Legacy pending access predate secure email invitations and are not converted automatically. Sign out and back in after a recent access change.

Related articles

Read Workspace Profile, Create your account, and Rights & Ownership overview.