Who can do what
Owner, admin, manager, member, and the rules that decide what a Talent is allowed to do on your behalf.
Work out which of the four seats each person needs, and you are done. TalentOS has no fine grained permission editor to configure, on purpose.
The rule underneath all of it: a seat gates authority, never participation. An admin is not a supervisor account with a different product. Everyone has their own Talent, their own connected tools, their own memory, and their own work. Higher seats simply add governance on top.
The four seats
Member. The everyday seat and the whole product. A member has their own Talent, connects their own apps, writes Routines and Skills, keeps their own memory, publishes to the Marketplace, and adopts from it. Every member sits in a department.
Admin. A member, plus governance of the workspace. Admins invite and remove members, create and archive departments, move people between them, assign manager seats, hold workspace settings, and read billing and workspace spend.
Manager. Not a role. A department scoped grant that sits on top of whatever someone already is, so a member or an admin can hold one. It adds a Manager group in the sidebar for the department they run, where they curate its shared memory. One manager per department.
Owner. Exactly one per workspace, and always an admin as well. The owner holds money and admin appointment. See What only the owner can do.
Pick the right one
| You want them to | Give them |
|---|---|
| Do the work, with their own Talent and tools | Member |
| Look after one department's shared knowledge | Member plus a manager seat |
| Invite people and run departments and settings | Admin |
| Change the plan or the card | They already need to be the owner |
Give admin to the people who actually administer, usually one or two in a team of 20. It buys them nothing extra as a practitioner, and it does not let them read anyone's work.
What a Talent may do
A Talent holds capabilities, never a role. It is a bounded subset of the authority of the person who owns it, and it can never exceed them.
- It acts as its owner, with their connected accounts. Priya's Talent reads Priya's email because Priya connected it, and it has no path to yours.
- It cannot publish work to the department or the company on its own. Widening an audience is a decision a person makes in the console.
- Consequential actions carry an approval step. See Approve what your Talent does.
- Talking to your Talent from a connected messaging channel gives it exactly the same authority it has in the web console, and no more.
A worked example
Priya runs Client Services but does not administer the workspace. Give her a member role plus the Client Services manager seat. She can use her own Talent, connect her own tools, and curate that department's shared memory. She cannot invite a new teammate or change billing, so an admin handles the invitation and the owner handles the plan.
What to check
Someone is missing a section of the sidebar. Sections are absent rather than disabled when a seat does not include them. Check their row in Team, Directory, and confirm the seat, then ask them to reload.
An admin cannot change a plan. Correct. Billing writes are owner only.
A control is visible but refuses. Every rule here is enforced on the server, not just in the interface, so the refusal is the real answer. The message names which seat the action needs.
Remove someone from the workspace
Offboard a person cleanly, know what happens to their seat and their work, and understand what you cannot remove.
What only the owner can do
The short list of powers that stop at one person, why admins see a note instead of a broken button, and what to do when the owner is away.