Permissions
Workspace Role Access
MyTabulon uses layered workspace roles so day-to-day contributors can work without receiving sensitive company memory, accounting, payroll, integrations, or ownership controls.
- Owner is the top business role. Owners can edit business settings and handle owner-only areas such as payout setup, ownership-level changes, deletion controls, and company management.
- Administrator can manage sensitive workspace operations such as Business Memory, company-wide AI Actions, AI Automations, Analytics, Accounting, Payroll, Imports, Team, Employees, Integrations, MCP, and Agent Skills, but business settings edits stay owner-only.
- Member can work in normal operating areas such as dashboard, Maximo chat, AI Images, AI Audio, AI Docs, CRM, pipeline, invoices, inventory, operations, tasks, calendar, files, support, billing visibility, and personal settings.
- Member File Manager and AI Docs are scoped to the signed-in user: members only see files, folders, source files, and AI document jobs they uploaded, added, or generated themselves, while storage and document-limit counters still reflect the full business plan usage.
- Member cannot view Business Memory, sensitive company context, accounting, payroll, analytics, automations, company-wide AI action history, imports, integrations, MCP, Agent Skills, team management, employee management, or business settings. Members can inspect, undo, and redo their own permitted Maximo AI actions from chat action history.
- Viewer is read-only for allowed workspace areas and cannot create, edit, delete, send, approve, export, connect, import, sync, run, refund, credit, or schedule actions.
- Viewer cannot use AI Images, AI Audio, AI Docs, or open sensitive owner/admin pages.
- Employee Viewer is narrower than Viewer: assigned tasks, calendar, support, personal profile, security, and notifications only until promoted.
- Hidden navigation is not the security layer. Backend APIs, Maximo tool access, live voice tool calls, global search, and background memory capture are role-gated too.

