Help / Workspace admin / What each capability lets someone do
What each capability lets someone do
Reference2 min
In one sentenceNobody has a role - each person holds capabilities, most arriving with a module the moment it is switched on, and two belonging to admins alone.
| Capability | Comes with | What it lets someone do |
|---|---|---|
deal.read | Sell | See deals, companies and contacts - the board, Today, search and the forecast |
deal.write | Sell | Create and edit deals, companies, contacts and line items; bring a book in from a spreadsheet |
deal.advance | Sell | Move a deal to another stage, or mark it won or lost |
hold.write | Sell | Put a deal on hold, and take it off again |
quote.write | Sell | Draft and send quotes |
import.write | Sell | Run an import |
pricing.evaluate | Sell | Price a rated offering - the one lookup a public form may call |
time.write | Time | Log hours on a deal or a bucket |
hr.read | People | See your reports, one-on-ones, flight risk and pay |
hr.write | People | Record a one-on-one |
candidate.read | Recruit | See campaigns and the candidate board |
candidate.write | Recruit | Add and edit candidates and their forms |
candidate.advance | Recruit | Move a candidate between stages, or withdraw them |
credential.write | Recruit | Record and update a candidate's credentials |
booking.write | Recruit | Book a candidate and record the outcome |
placement.write | Recruit | Record a placement, and end one |
intake.write | API tokens only | Send deals in from a form or your website |
propose.write | API tokens only | Suggest a move for a person to approve |
token.mint | Make developer | Mint API tokens, never wider than their own reach |
deal.delete | Admins | Delete a deal for good |
workspace.write | Admins | Everything under Admin - members, teams, modules, pipelines, billing |
Scope is a dimension of deal.read, not a separate permission: the workspace floor under Everyone sees on General is their own deals, their team's deals or the whole book, and a grant on Roles & members can only widen it for one person. Switching a module off takes its capabilities away from everyone at once and keeps the data; an API token never gains a capability from a module being switched on.
Did this answer it? Not quite - tell us