The three dimensions
Resource
What is being protected:Action
What can be done: view, create, edit, or delete.Scope
How much of the resource the grant covers:
Scope is the dimension people underestimate. “Can view accounts” is not one permission — viewing every account in the business and viewing the twelve you own are very different grants, and the difference is scope.
Built-in permission sets
Three sets ship with every workspace and cover the common cases.Owner
Full control. Manages billing, transfers ownership, and can change any other member’s access. Exactly one per workspace, assigned to whoever created it.Admin
Manages the workspace day to day: members, teams, integrations, and settings, with access across all accounts. Cannot manage billing or transfer ownership.Member
The working set for a CSM or account owner. Views and works accounts, signals, tasks, and reports, typically scoped to their own or their team’s accounts. Cannot change integrations, membership, or workspace settings.Custom permission sets
Where the built-in three do not fit, custom sets can be defined. Common shapes:- Read-only stakeholder — view across all accounts, create and edit nothing
- Regional lead — full working access scoped to
team - Integrations owner — manage integrations without account-level access
- Analyst — view everything, generate reports, change nothing
Creating and assigning permission sets requires admin access. Talk to your workspace admin or your Superhawk representative about a set you need.
Teams and scoped access
Scoped permissions only do useful work when teams are set up, becauseteam scope resolves through team membership. A workspace with everyone in no team effectively has only all and own available.