Everyone in a Tandem App workspace has one of four roles: owner, admin, member or guest. The role decides what they can see and manage across the workspace. Guests also have an access level in each channel. This guide sets out who can do what.
Owner
The person who created the workspace is its first owner, and there can be more than one. Owners can do everything an admin can, plus:
- Make other people owners or admins, and manage other owners and admins.
- Import from Slack, Export your data and Close this workspace, all under Workspace settings.
Admin
Admins run the workspace day to day. They can:
- Invite members and guests, and deactivate or reactivate them.
- Create channels, change their settings, archive and restore them.
- Change the plan, update the card and billing details, and see invoices.
- Change the workspace name, address and logo.
- Set up incoming webhooks, custom slash commands and workflows under Apps and workflows.
- Delete other people's messages in channels when moderating.
An admin can never change an owner or another admin, so one compromised admin account can't promote itself or lock the owner out.
Member
Members are your team. They can:
- Browse and join any public channel, and leave channels.
- Chat, start threads, react, pin, run polls and send direct and group messages.
- Create and edit tasks and upload files in the channels they are in.
- Edit and delete their own messages.
Members can't create channels or invite people; ask an owner or admin.
Guest
Guests are people from outside the company, such as clients or freelancers. A guest sees only the channels they have been added to, can't join channels by themselves, and can't send or receive direct messages. In each channel a guest has one of three access levels:
- Full access — can chat and edit tasks and docs.
- Chat only — can chat; tasks and docs are view-only. This is where guests start.
- Read only — can read everything but not post or edit.
Guests are free, up to 5 for every paid user. See working with clients as guests.
Private channels and direct messages
A private channel is hidden from members and guests who aren't in it. Owners and admins can open every channel, including private ones, but only the person who created a private channel can add people to it. If that person is no longer an owner or admin, an owner can stand in.
Direct and group messages are different: they belong only to the people in them. Owners and admins get no special access to them.
Two-step sign-in for owners and admins
Because owners and admins hold the keys to everyone's access, they must turn on two-step sign-in before they can open the Admin dashboard, the admin pages or Apps and workflows.
Changing someone's role
- Open Admin dashboard and go to People.
- Click Roles and access dates.
- Use Change role on the person's row and pick the new role.
The same page lets you set a guest's access end date and reset someone's two-step sign-in if they have lost their phone. Every change is recorded in the audit log, alongside sign-ins, invitations and channel changes.