Members, roles and capabilities
Who can do what, and how to scope it precisely.
Foreman has three roles and about forty individual capabilities. The roles are defaults; the capabilities are the truth.
The roles
| Role | What it means |
|---|---|
| Owner | Everything, including deleting the workspace and transferring ownership |
| Admin | Everything except those two |
| Member | Day-to-day work: chat, their own agents, resolving escalations and handoffs, routines and automations |
Members deliberately do not get: billing, financial data, CRM schema changes, external sync configuration, workspace memory, Studio project management, database connection, or device storage relocation. Each of those either reshapes the workspace for everyone or exposes data as sensitive as billing.
Overrides
You can grant or revoke individual capabilities per member without changing their role. That is the right tool when someone needs exactly one extra power — a member who should manage the inbox, say — rather than promoting them to admin.
Steps
- Settings → Members to invite someone and set a role.
- Open a member to adjust individual capabilities.
- Check the result from their side: the surfaces they cannot use disappear rather than erroring.
You're done when a member sees exactly the surfaces they need and none they don't.
Gotchas
- Capabilities hide, they don't grey out. A member without a capability doesn't see a disabled button — the surface isn't there. That is deliberate: a checklist you cannot finish is worse than one you cannot see.
- Approval capabilities are separate per type. Being able to resolve an escalation does not let someone approve a budget change.