Settings and AI configuration

Members, roles and capabilities

Who can do what, and how to scope it precisely.

About 6 minutes

Foreman has three roles and about forty individual capabilities. The roles are defaults; the capabilities are the truth.

The roles

RoleWhat it means
OwnerEverything, including deleting the workspace and transferring ownership
AdminEverything except those two
MemberDay-to-day work: chat, their own agents, resolving escalations and handoffs, routines and automations

Members deliberately do not get: billing, financial data, CRM schema changes, external sync configuration, workspace memory, Studio project management, database connection, or device storage relocation. Each of those either reshapes the workspace for everyone or exposes data as sensitive as billing.

Overrides

You can grant or revoke individual capabilities per member without changing their role. That is the right tool when someone needs exactly one extra power — a member who should manage the inbox, say — rather than promoting them to admin.

Steps

  1. Settings → Members to invite someone and set a role.
  2. Open a member to adjust individual capabilities.
  3. Check the result from their side: the surfaces they cannot use disappear rather than erroring.

You're done when a member sees exactly the surfaces they need and none they don't.

Gotchas

  • Capabilities hide, they don't grey out. A member without a capability doesn't see a disabled button — the surface isn't there. That is deliberate: a checklist you cannot finish is worse than one you cannot see.
  • Approval capabilities are separate per type. Being able to resolve an escalation does not let someone approve a budget change.

Checked against

  • helpers/humanPermissions.tsx