
System permissions are a separate layer from feature permissions. A member can have full access to the Workflow Builder but no ability to manage users — these are completely independent settings within a permission set.
| Permission | What it allows |
|---|---|
| User management | Invite members, deactivate accounts, and change team membership |
| Permissions settings | Create and edit permission sets; assign members to sets |
| Billing and usage | View subscription status and usage metrics |
| Manage integrations | Connect and configure third-party integrations |
Each system permission has its own access level:
| Level | What it means |
|---|---|
| Full access | Can perform all actions for that capability |
| Read only | Can view but not change anything |
| None | The capability is not accessible |
A member with read-only access to Permissions Settings can see what permission sets exist and who belongs to each one. They cannot create new sets, edit existing ones, or reassign members. This is useful for team leads who need visibility into access configurations without the ability to change them.
One permission set type sits above all individual rules: the System type. Members assigned to a System-type permission set have unconditional full access to every feature and admin capability in the workspace — no individual feature or system permission configuration applies.
Use this sparingly. It is intended for:
Assigning routine users to a System-type set bypasses all access controls entirely. You can identify a System-type set in Settings > Permissions — it is labelled distinctly from standard permission sets.