Roles & Permissions
Rasveon has five roles that control what someone can do inside your workspace, plus one account owner flag that controls billing and workspace-level decisions.
The five rolesβ
Roles are ranked. Higher rank includes everything the lower ranks can do, plus more.
| Rank | Role | What they can do |
|---|---|---|
| 0 | Viewer | Read everything. Cannot create, edit, or delete anything. |
| 1 | User | Create records. Edit records they own. Cannot edit other people's records. |
| 2 | Senior | Everything User does, plus edit anyone's records. |
| 3 | Manager | Everything Senior does, plus reassign records, invite users, edit team settings, view team reports. |
| 4 | Admin | Everything Manager does, plus manage roles, delete records, and configure workspace-wide settings. |
The Account Owner flagβ
Separate from the role hierarchy is the is_owner flag. There's always exactly one account owner at any given time in the workspace. The owner can:
- Change the plan (upgrade / downgrade / cancel)
- Manage payment methods
- Schedule workspace deletion (see Workspace Settings)
- Transfer ownership to another admin
The owner must be an admin. If ownership is transferred, both parties keep their admin role β only the flag moves.
If the owner leaves the company or loses email access, another admin can request an ownership transfer from Rasveon support. This requires identity verification and is not automatic.
What each role sees in the UIβ
Viewerβ
- All read pages (Leads, Customers, Opportunities, Reports)
- No "Create" or "Edit" buttons anywhere
- The AI can only run read skills β search, lookups, reports
Userβ
- Same read access as Viewer
- Can create new records
- On records they don't own: can view but the fields are read-only
- The AI will refuse to update someone else's record with a clear message
Seniorβ
- Full edit rights on any record
- Cannot reassign records between users (that's a Manager action)
- Cannot invite new users
Managerβ
- Full edit and reassign rights
- Can invite new users up to their own rank (a Manager can invite Users and Seniors, not other Managers)
- Can view team-level reports
- Can configure Sources, Pipeline stages, and Lead Statuses
Adminβ
- Everything the Manager can do
- Manage user roles (promote, demote)
- Delete any record (with confirmation)
- Configure workspace-wide settings
- Access Settings β Advanced
Changing someone's roleβ
Only admins can change roles. Go to Settings β Users, find the user, click the role dropdown.

A demotion doesn't remove history β activities they logged, records they created, notes they wrote all stay attributed to them.
Trial and read-only modeβ
If your subscription trial expires without a plan, the workspace goes into read-only mode β everyone becomes effectively a Viewer until the account owner subscribes.
This is not a role change β the users' actual roles are preserved. Once you subscribe, everything works again.
Permissions and the AIβ
The AI respects all role rules. If a User asks the AI to edit a lead they don't own, the AI will respond with something like:
"I couldn't update that lead β it's assigned to Sarah. Ask Sarah, or a senior/manager, to help."
The AI will never impersonate a higher role or bypass a permission check.
Best practice for team structuresβ
For a typical field service business of 10-20 people, we suggest:
- 1 Admin β the business owner or operations manager, also the account owner
- 1 Manager β the sales lead or head of installations
- 2-4 Seniors β experienced technicians and sales reps
- All others as User β new hires, junior staff
- Viewer β accountants, external partners who need visibility but shouldn't edit
Read next: Workspace Settings β for what admins can configure.