Those are the names you’ll see in the role picker and on member badges throughout the app. Internally — in the database and a few API contexts — the same three tiers are named Owner, Admin, and Member. If you ever see “Admin” or “Member” referenced (for example in an error message), it maps directly to Account manager and Customer success respectively.
How the hierarchy works
Roles are ranked Owner > Account manager > Customer success. A member can only manage people below their own rank. An Account manager can change a Customer success member’s role or remove them, but cannot touch another Account manager or the Owner. Only the Owner can promote someone to Account manager or manage another Account manager’s access.Owner
There is exactly one Owner per workspace: the person who created it, or whoever it was transferred to since. The Owner has every capability below plus:- Managing billing and the subscription plan
- Transferring ownership to another member
- Deleting the organization (on deployments where organization deletion is enabled)
Account manager
Account managers handle day-to-day team and workspace operations. They can:- Invite new members as Account manager or Customer success, and manage pending invites
- Change the role of, or remove, any Customer success member (but not another Account manager or the Owner)
- Manage billing and the subscription plan — billing access isn’t Owner-exclusive
- View Team performance analytics (the per-agent leaderboard under Analytics > Performance), which is hidden from Customer success members entirely
Customer success
Customer success is the default role for most team members — everyone doing hands-on review work. They have full access to:- Reviews, replies, and AI-assisted response generation
- Automations, templates, the knowledge base, and topics
- Analytics and reporting (aside from the Team performance leaderboard, which is Account-manager-and-up only)
Manage members
Invite teammates, change roles, and manage pending invites
Security
Multi-factor authentication and how credentials are stored