Workspace & team
Invite people and control what they can do.
Almost nobody runs a calling operation alone. Someone builds the agents, someone loads the campaigns, someone watches the money, and someone signs off on compliance. A workspace lets your whole team work in one place - while making sure each person can only touch the parts that are actually their job.
You do all of this under Account → Team members (and a couple of related tabs). A teammate you invite gets an email, joins your workspace, and immediately sees exactly what you decided they should see - no more, no less.
This guide covers who can do what (roles), how to fine-tune a person’s access (per-area permissions), inviting and managing people, handing over the keys (ownership), belonging to more than one workspace, and the danger zone.
New here? Creating an account, your free signup credit, and KYB verification are covered in Sign up & workspace. This page picks up once the workspace exists and you want to bring people in.
Roles: the three levels of access
Everyone in a workspace has one of three roles. The role is the big, coarse dial - it decides most of what a person can do before you touch any fine-grained settings.
Owner
The person in charge. There is exactly one owner per workspace, and that’s a hard rule the platform enforces - you can’t accidentally end up with two owners or zero.
- What they can do: everything. Every module, plus the owner-only actions no one else gets - transferring ownership, closing the workspace, and promoting or managing admins.
- Who becomes one: whoever created the workspace at signup. Ownership only moves when you deliberately hand it over (see Transferring ownership).
Admin
Your trusted operators. An admin can run the whole workspace day-to-day.
- What they can do: full access to every module - agents, campaigns, numbers, billing, compliance, knowledge, analytics, settings - plus they can invite and manage other people.
- What they can’t do: the owner-only stuff. An admin can’t transfer ownership, close the workspace, or manage other admins. An admin can invite and manage members, but only an owner can invite an admin or change an admin’s access.
Rule of thumb: give admin to the handful of people you’d trust with the whole account. Everyone else should be a member with just the access they need.
Member
Everyone else - and the role where per-area permissions come in. A member starts with no access to anything until you grant it, area by area.
- What they can do: exactly what you switch on for them, and nothing more. You might let someone read analytics and run campaigns, but never see billing.
- Why it matters: this is how you bring in a campaign runner, a contractor, or a junior teammate without exposing your wallet, your carrier setup, or your compliance rules.
The next section explains how to dial in a member’s access.
Per-area permissions (for members)
Owners and admins have full access automatically, so there’s nothing to configure for them. For members, you decide access one area at a time using the “Access per area” grid that appears in the invite and edit dialogs.
There are eight areas you can control:
- Agents - building and editing voice agents
- Campaigns - creating and running outbound campaigns
- Numbers - buying and managing phone numbers
- Billing - the wallet, top-ups, invoices
- Compliance - compliance packs and gate rules
- Knowledge - knowledge bases the agents read from
- Analytics - call results, reports, dashboards
- Settings - workspace settings, API keys, webhooks
For each area you pick one of four levels:
- No access - the person can’t see or touch this area at all (this is the default).
- Read - they can look but not change. Good for someone who needs to see results without editing anything.
- Read and write - they can view and make changes - the everyday working level for most people.
- Admin - full control of that one area, including its most sensitive actions.
Think of it as read < write < admin: each level includes everything below it. So “Read and write” on Campaigns lets a person both view and run campaigns, while “Read” on Analytics lets them study results without changing a thing.
A realistic setup: a campaign runner might get Campaigns: Read and write, Agents: Read, Analytics: Read, and No access to Billing, Numbers, and Settings. They can do their job every day and never see a rupee of your wallet.
- Tip: grant the least that lets someone do their job. It’s quick to add more access later from the same edit screen, and it’s the safer default.
- Note: contacts aren’t a separate permission - they travel with campaigns. And managing people isn’t a per-area toggle either; it’s tied to being an owner or admin.
Inviting teammates
You invite people by email from Account → Team members. Only owners and admins can send invites.
- Click Invite a member.
- Enter their email address.
- Pick a role. Members can be invited by any owner or admin; the Admin option only appears if you are the owner (only owners can create admins).
- If you chose Member, set their Access per area using the grid described above.
- Hit Send invite.
The person gets an email with a secure link. When they click it and sign in (or sign up) with that same email, they join your workspace with the exact role and access you set. The invite link is good for 7 days, then it expires.
A few things worth knowing:
- It has to be their email. The invite is locked to the address you typed - someone can’t accept an invite meant for a different email.
- Pending invites are visible. Before someone accepts, they show up in your team list with a “Pending” tag and an expiry date, so you always know who’s outstanding.
- You can revoke. Changed your mind, or invited the wrong address? Revoke the pending invite from its row and the link stops working. (There’s no separate “resend” - if a link expires, just revoke and invite again.)
- The same email can be in many workspaces. Inviting someone who already uses oyehello elsewhere is fine - they’ll simply gain access to yours too (see Belonging to more than one workspace).
You can’t double-invite. If the email is already a member here, or already has a pending invite, the platform tells you instead of creating a duplicate.
Managing people
Every person in your team list has a ⋯ menu with two actions: Edit and Remove.
Change someone’s role or access
Choose Edit to open that person’s settings. You can switch their role (Member ↔ Admin - the Admin option is owner-only) and, for members, adjust the per-area access grid. Save, and the change takes effect the next time they load the app.
Guardrails the platform enforces so nobody paints themselves into a corner:
- You can’t edit yourself here - no accidentally demoting your own access.
- You can’t edit the owner’s access (the owner’s power comes from being the owner).
- Only an owner can edit an admin. Admins can only manage members.
Remove someone
Choose Remove to revoke a person’s access to the workspace entirely. The same guardrails apply, plus:
- You can’t remove yourself (to leave, use Belonging to more than one workspace).
- You can’t remove the owner - ownership has to be transferred first.
- Only an owner can remove an admin.
Removing is reversible in practice - the person simply loses access. If it was a mistake, invite them back and they’ll rejoin.
Transferring ownership
Because there’s only ever one owner, handing over the workspace is a deliberate, explicit step. It lives in the danger zone (Account → Danger zone), and only the current owner can do it.
Here’s what happens:
- Under Transfer ownership, pick an existing member from the list. (If you’re the only person in the workspace, you’ll be prompted to invite a teammate first - you can’t transfer to nobody.)
- Confirm. The platform asks you to acknowledge that you’ll be demoted to an admin and can’t undo this yourself.
- Done - in one atomic step the other person becomes the owner and you become an admin.
This is a one-way door for you. Once you transfer, you’re an admin. If you want ownership back, the new owner has to transfer it to you. So transfer to someone you genuinely trust with the whole account.
Leaving as the only owner is a related case. If you’re the sole owner and you try to leave the workspace, you can’t just walk out and leave it ownerless - you’ll be asked to hand off ownership to an admin on the way out. If there are no admins yet, promote a member to admin first (or close the workspace from the danger zone).
Belonging to more than one workspace
One email can belong to several workspaces - handy if you run separate brands, manage clients, or keep a sandbox apart from production. Each workspace keeps its own agents, numbers, contacts, billing, and your role in each can differ (you might own one and be a member of another).
- Switch between them with the workspace switcher at the top of the sidebar, or from Account → Workspaces. When you switch, your whole session re-scopes to the chosen workspace - the data you see, the permissions you have, and the wallet you’re spending all follow.
- Everything is isolated. Nothing leaks between workspaces. Calls, contacts, credit, and settings all stay put where they belong.
- Leaving a workspace you no longer need is done from Account → Workspaces (not the switcher). You’ll lose access until someone invites you back - and if you’re the sole owner, see the ownership hand-off above first.
No “create workspace” button in the console (yet). New workspaces come from signing up. If you need another one, start a fresh signup, then use the switcher to move between them.
The danger zone
Account → Danger zone holds the high-impact, owner-only actions. It’s walled off on purpose and everything here asks you to confirm. There are two things you can do:
Transfer ownership
Covered above - hand the workspace to another member and step down to admin.
Close the workspace
This suspends the entire workspace: agents stop calling, campaigns halt, and you can’t buy new numbers. It’s the “we’re done here” button.
- How it works: click Close workspace, then type the workspace’s exact name to confirm - a deliberate friction step so it can’t happen by accident.
- What happens to numbers: your phone numbers stay reserved for 30 days, then return to the carrier.
- It’s reversible - for a while. Closing suspends rather than permanently deletes. If you change your mind, contact support within 30 days to reopen. After that, it’s gone.
Closing is not the same as leaving. Leaving removes just you from a workspace that keeps running. Closing shuts the whole workspace down for everyone.
Next: API keys → - generate keys and drive oyehello programmatically from your own systems.