Roles and access

Four layers decide what each person can open and what they can do inside.

Eel decides access in four layers, and each layer has exactly one job. Mixing them up is the usual source of "I thought this person could".

Who can use this? The workspace owner and its admins hand out roles and access. If you do not see these panels, talk to one of them.

Layer 1: the workspace role

Pick each person's workspace role from Owner, Admin and Member: this layer decides who joins, who leaves, and who changes everyone else's access. It governs people, not what happens inside an app.

Role What they can do
Owner Everything an admin can. There is always at least one.
Admin Invite, remove people, change roles and access, edit the workspace.
Member Do the work. Sees the member list but does not change it.

Layer 2: app access

Open a member's Access and roles panel and grant the apps one by one: one row per app, and the role you pick there decides what they can do inside. App access is separate from the workspace role. The same panel appears when you invite or add somebody, so it is all set before they arrive.

Leave the select on No access and that person never sees the app on the rail or reaches its pages. This is how you keep a Wrap operator out of Flow's accounting.

You grant Wrap, Flow, Swarm and Zap this way. Not Nest: it is the hub where your profile, your alerts and workspace switching live, and every member reaches it by definition.

Workspace owners and admins have access to every app, always, and as app admins. There is no way to keep an admin out of an app.

One member's per-app access panel: the four app rows with their role selects.

Layer 3: the role inside the app

Inside each app you can open, you are either Member or Admin.

  • Member does the work. It is the default and covers almost everything.
  • App admin holds that app's elevated levers: its settings page, moderation and the restricted actions.

An app admin administers the app, never the people or the seats.

Layer 4: per-object permissions

In the last layer, each channel, project and conversation decides on its own who gets in:

  • A Swarm channel has its own members and its managers.
  • A Swarm project has its members and its lead.
  • A Wrap conversation is shared with named people.

Being an app admin does not put you inside a private channel you are not a member of. Ask somebody inside to add you.

Revoking access deletes nothing

Revoke access to an app and nothing else goes with it: what the person wrote, their memberships and their preferences all stay. Grant it again tomorrow and everything is where they left it.