Team, roles & approvals
Inviting people, exactly what each of the four roles can do, and how the approval queue lets members draft sends that admins review.
Open TeamOne organisation, one owner, and as many people as your plan allows. The point of this page is that a committee member can help without being able to broadcast to the entire association unreviewed.
Roles#
Four roles. They're fixed — there's no permission matrix to configure, which is deliberate: role-based is easier to reason about than per-user checkboxes, and an org chart nobody understands is how accidents happen.
| Owner | Admin | Member | Viewer | |
|---|---|---|---|---|
| Send on the shared number | direct | direct | needs approval | no |
| Create events, campaigns, scheduled sends | yes | yes | needs approval | no |
| Approve or reject requests | yes | yes | no | no |
| Manage groups, tags, caps | yes | yes | no | no |
| Invite people | yes | yes | no | no |
| Promote or demote admins | yes | no | no | no |
| Billing and plan changes | yes | no | no | no |
| Delete the organisation | yes | no | no | no |
Notes:
- The owner is the person who signed up. You can't reassign it by editing a user's role — but the owner can hand it over deliberately, via transfer ownership in Settings. That's the route to use at a board handover.
- Admins can do everything operational — send, approve, manage groups and tags, invite. They can't touch billing or change who else is an admin.
- Members are the interesting case: they can build and draft everything, but on the shared number their actions become requests. See below.
- Viewers read. Useful for a treasurer or a board member who wants visibility with no ability to send.
Inviting people requires an active subscription, and the number of seats depends on your plan — see Plans & billing.
Inviting people#
Send an invite by email from the Team section. The invitee gets a link, sets a password, and lands in your organisation with the role you chose. You can change a role later, or remove someone — removing a user immediately revokes their access, including any API tokens they'd created.
The approval queue#
This is the mechanism that makes a shared number safe.
When a member sends, schedules, repeats, fires a campaign, or requests an event launch on the shared number, nothing goes to WhatsApp. Instead a pending request is created, and admins see it in Approvals.
An admin reviewing a request sees the actual thing: the message, the audience it resolves to, the schedule. Approve and it proceeds exactly as if an admin had done it. Reject and it doesn't.
Details worth knowing:
- Event launch requests can't be double-submitted. Once one is in, the button reads "Pending approval" and stays disabled until it's decided. Compose requests have no such guard, so a member who clicks twice can create two pending requests — approve one and reject the other.
- Admins bypass the queue entirely — an admin's send is a send.
- A member with their own number doesn't need approval for that number. The queue exists to protect the shared one.
- Approval doesn't skip the gates. An approved send still passes caps, cooldown, and quiet hours like any other.
When to use it#
Use approvals whenever more than about three people can send. The failure mode it prevents isn't malice, it's a committee member with good intentions sending the fourth message about the same party to a year group that has already muted you.
If your whole team is trusted and small, make them admins and skip the ceremony.
Member hub#
Members get a simplified home showing what they can actually do: their drafts, their pending requests, and what's been approved. It exists so a committee member isn't dropped into an operator dashboard full of controls they can't use.
A worked setup: Shared number, many senders.