Skip to main content
Roles ensure users only access the features necessary for their job.

Create roles

  1. In Spott, go to Settings.
  2. In the Admin section, click Security.
The Security page with Workspace Roles
Under Workspace Roles you can:
  • Open existing roles
  • Create new ones with the New role button
Click a role to open it. For each role, use the toggles to enable the permissions that role should have, grouped per area (records, settings, analytics, exports, and more). For example, you may want to grant team leads access to workspace settings (to create new fields) while restricting this for regular members, or control who can view, manage, and export Analytics Reports.
A role's permission toggles

Permissions people go looking for

Most permissions do what their name says. These come up often, because the action they gate simply disappears or fails rather than explaining itself:
  • AI assistant connection. Connecting Spott to Claude or ChatGPT is its own permission, separate from the record access the connector inherits. Without it a user completes the sign-in normally and then every request comes back as MCP_ACCESS_DENIED. See Spott MCP.
  • Delete Job. Without it, the delete option on a job is greyed out rather than hidden, so it looks like a fault.
  • Enrichment. Switching it off for a role is the only way to control who spends credits, since the balance is a single pool with no per-user limit. See profile enrichment.
  • Merging records. Merging two candidates, contacts, or companies needs its own permission, and without it the merge fails at the last step.
  • Company hierarchies. Creating and editing a company hierarchy is its own permission, so you can let a team read a client group’s structure without letting them reorganize it. On a large account the tree is shared reference data, and one person reparenting an entity changes what everyone else sees.
Two things only an admin can do, whatever you grant. Seeing every user in the workspace is admin-only: for a manager who needs other teams’ figures without full admin, grant Manage Analytic Reports, which opens the team and user filters on the Dashboard and in reports. And you cannot remove your own role, so a second admin has to make that change for you.

Add a user

  1. In Spott, go to Settings.
  2. In the Admin section, click Users.
  3. Invite the person by email address and give them a role.
They receive an invite link, create their password, and are in. From then on they can also sign in with Microsoft or Google. See personal preferences.
Removing a user deactivates them rather than deleting the account, so their historical activity stays attributed to them.

Assign roles to users

  1. In Spott, go to Settings.
  2. In the Admin section, click Users.
Assigning a role to a user
Use the role dropdown next to a user to assign them a role, which automatically grants the matching permissions. When a user holds more than one role, their permissions combine: the roles add up rather than restrict each other.
Admin is a built-in role with full permissions. It cannot be deleted or reduced, and there must always be at least one admin in the workspace.

Multi-factor authentication

On the Security page you can require multi-factor authentication for your whole workspace. Users then add an authenticator app to their own profile the next time they sign in.