Workspaces · roles · activity log

Stop sharing the social media password

Invite people into a workspace with a role that matches what they should actually be able to do. Connected accounts stay encrypted and untouchable; the calendar, the brand kits and the history are shared.

Northwind · members
  • ARAditi R.Owner
  • MKMarcus K.Admin
  • JDJules D.Scheduler
  • SPSam P. (client)Visitor
Ranked permissions

Four roles, and nobody can act on someone above them

Roles are ranked rather than flat. An Admin cannot remove another Admin, and only the Owner outranks everyone — so a compromised account cannot escalate sideways.

Owner

Rank 40
  • Everything an Admin can do
  • Manage billing and the plan
  • Transfer ownership
  • Delete the workspace

The person whose card is on file. One per workspace.

Admin

Rank 30
  • Invite, remove and re-role people
  • Connect and disconnect social accounts
  • Edit brand kits
  • Write, schedule and publish

Your social lead, or the account manager who owns a client.

Scheduler

Rank 20
  • Write, schedule and publish posts
  • Use the AI agent
  • Move posts on the calendar
  • Manage people
  • Connect or disconnect accounts

Writers, contractors and freelancers doing the actual posting.

Visitor

Rank 10
  • Read posts, the calendar, brand kits and activity
  • Change anything at all

A client who wants visibility, or a stakeholder who wants to look without touching.

Isolation, not folders

A workspace is a wall, not a label

Each workspace carries its own connected accounts, brand kits, calendar, members, API keys and activity. A freelancer invited into one client’s workspace has no path to another client’s accounts — not a hidden tab, not an API call, nothing.

Billing stays on one account, so multiplying workspaces does not multiply invoices.

Read the agency setup
PlanCollaboratorsWorkspacesProfiles
Free115
Starter5310
Professional10525
Business201050

Every change is attributed

The activity log records who scheduled, edited, moved or deleted a post — including the AI agent, which shows up as its own author.

Credentials never leave the vault

OAuth tokens and app passwords are encrypted server-side. No role, including Owner, can read them back out.

One calendar, many hands

Contractor drafts, teammate schedules and agent proposals all land on the same board, each with an author badge.

Team and permissions FAQ

How do I let someone post for me without giving them my password?+

Invite them to the workspace by email and give them the Scheduler role. The social account credentials stay encrypted server-side and are never shown to anyone — a Scheduler can publish through connected accounts but cannot see, export or disconnect them.

What are the roles and what can each one do?+

Four ranked roles. Owner controls billing and the workspace itself. Admin manages people, connections and brand kits, and publishes. Scheduler writes, schedules, publishes and uses the AI agent, but cannot touch people or connections. Visitor is read-only. A member can never act on someone at or above their own rank — the Owner being the exception.

Can I keep clients separate from each other?+

That is what workspaces are for. Each workspace has its own connected accounts, brand kits, calendar, members and activity log. A contractor invited into one client’s workspace sees nothing from the others, and billing stays on one account.

Is there an approval step before something publishes?+

Yes for AI-driven work: anything the agent wants to publish, edit, reschedule or delete surfaces as an approval a human accepts or rejects. For human authors, the review model is the shared calendar — drafts and scheduled posts are visible and editable by the team until they go out.

Can I see who scheduled a post?+

Every post carries its author, and the workspace keeps an activity log of what changed and who changed it. On a shared calendar with a contractor, a teammate and an AI agent all writing, that provenance is the difference between a review and an investigation.

How many people can I add?+

Free includes 1 collaborator, Starter 5, Professional 10 and Business 20 — alongside 1, 3, 5 and 10 workspaces respectively. Seats are per workspace membership, so a contractor in two of your workspaces uses two.