DocsTeam & operations › Team & roles

Set up team & roles

In this guide you invite colleagues, assign roles and control exactly who may see and do what — including brand assignment and optionally mandatory two-factor sign-in.

⏱ approx. 5–10 min · Permission: roles.manage (admin) · Free (up to 3 users) & Paid (unlimited)

Settings → Team in The-Y CRM
Settings → Team — invite, roles and permissions.

Invite members

  1. Open Team. Settings → Team.
  2. Invite. "+ Invite": choose email, name and role. The person receives an invitation link and sets their own password on first open — so you never share a password.
  3. Track status. Open invitations appear in the list; you can resend or revoke them. Accepted members show up as active users.
Free is limited to 3 users; on Paid the team size is unlimited.

Roles & visibility (scope)

Each person has one or more roles. The scope determines whose data (contacts/deals/tickets) they access.

RoleTypically allowedScope
Admineverything — incl. settings, team, billing, integrationsall
SupervisorCRM + analytics for the whole team, approvals (e.g. leave), no operator settingsall / team
Agentedit own contacts/deals, answer ticketsown (or team)

Scope: own (only what's assigned to/owned by me), team (my team), all (the whole tenant). "Owned by me" means: assignee or creator.

Fine-tune rights per person (overrides)

In addition to the role, you fine-tune individual rights per person — in the member editor, set each right to inherit (from the role), allow or deny.

Deny beats allow. Example: an agent should exceptionally be able to see companies → set the right company.view to "allow". Conversely, block specific actions with "deny".

Rights apply everywhere: menu items are hidden, "new/edit/delete" buttons disappear, and the server checks every action (no bypass via the URL).

Assign brands/workspaces

If you have multiple brands (workspaces), you assign in the member editor under "Workspaces" which brands a person sees. Agents only see the inboxes of their brands; admin/supervisor see all. That way you cleanly separate multiple customer brands, for example — one bill, multiple brands.

Enforce two-factor sign-in (2FA)

Troubleshooting

The invitation link no longer works

Invitations expire or may have been revoked. Simply resend the invitation in Settings → Team. (Invitation emails need a configured system mailbox; if none is set, give the person the link directly.)

I can't change my own role

This is intentional: changing your own role/rights is blocked so you can't accidentally lock yourself out. Another admin can change it (multiple admins are equal-rank).

An agent sees too little or too much

This is controlled by the scope (own/team/all) plus the overrides. For "own customers only" → scope own. For targeted exceptions, set individual rights to allow/deny.

Someone is locked out by 2FA

First sign in with a recovery code. If that's not possible, an admin resets the person's 2FA in Settings → Team; then they set up 2FA again.

What's next