# Roles and permissions

Everyone in a workspace has one role there, Owner, Admin, Editor or Viewer. This table shows exactly what each role can do in Heropost, and how to change someone's role.

Last checked: Oct 8, 2026 on the live app. Source: https://heropost.ai/docs/team/roles-and-permissions/

## The four roles

Everyone in a workspace has one role there. The same person can be an Editor in one workspace and an Admin in another.

| Role | In short |
|---|---|
| **Owner** | The login that owns the workspace. Can do everything, and the workspace runs on the owner's plan. Each workspace has one owner, and that can't be changed. |
| **Admin** | Runs the workspace with the owner: invites and removes people, approves posts, publishes and schedules, connects social accounts and AI tools, and manages automations. |
| **Editor** | Writes and edits posts, then submits them for approval. Can't publish or schedule from the post editor, approve posts, delete posts, connect accounts or manage automations. |
| **Viewer** | Sees the workspace's posts, calendar and analytics, comments in the Feed and uses the Social Inbox. Can't create or change posts. |

You choose the role when you [invite someone](/docs/team/invite-your-team/), and you can change it at any time.

## What each role can do

| Action | Owner | Admin | Editor | Viewer |
|---|---|---|---|---|
| See the calendar, Feed, drafts and analytics | Yes | Yes | Yes | Yes |
| Read and reply in the Social Inbox | Yes | Yes | Yes | Yes |
| Comment on posts in the Feed | Yes | Yes | Yes | Yes |
| Delete other people's comments | Yes | Yes | No (own only) | No (own only) |
| Create and edit draft posts | Yes | Yes | Yes | No |
| Submit a post for approval | Not needed | Not needed | Yes | No |
| Publish or schedule from the post editor (**Publish All**, **Schedule All**) | Yes | Yes | No | No |
| **Publish now** from the calendar | Yes | Yes | No | No |
| Approve or reject submitted posts | Yes | Yes | No | No |
| Take a post back out of review | Any post | Any post | Their own | No |
| **Edit** or **Duplicate** a post from the calendar, or drag a scheduled post to another day or time | Yes | Yes | Yes | No |
| Delete posts | Yes | Yes | No | No |
| Upload and delete files in the Media Library | Yes | Yes | Yes | No (browse only) |
| Use the Caption Library and Post Groups | Yes | Yes | Yes | No |
| Make photos and videos with Hero_Photo | Yes | Yes | Yes | No |
| Have Hero_Agent schedule or publish posts | Yes | Yes | No | No |
| Connect social accounts (**Add Profile**, **Invite Profile**) or remove them | Yes | Yes | No | No |
| Create, edit and delete automations | Yes | Yes | No | No |
| Connect AI tools | Yes | Yes | No | No |
| Invite people, change roles, remove members | Yes | Yes | No | No |
| **Settings**, **Accounts**, **Members** and **Watermark** in the workspace menu | Yes | No¹ | No | No |
| Billing | Their own | Their own | Their own | Their own |

¹ Those four buttons show only to the owner. Admins manage people from the **Team** menu, open the social accounts page at app.heropost.io/social-accounts, and can change the workspace's name, time zone and picture on a phone (**Workspace** tab → **Settings**).

## Change someone's role

Only the owner and Admins can change roles.

1. Switch to the workspace, then open **Team → Members**.
2. Click the role chip on the person's row ("Click to change role").
3. Choose **Admin**, **Editor** or **Viewer**. It saves straight away: **Role updated to {role}**.

[Screenshot: Team Members with a role chip open, showing Admin, Editor and Viewer]

On a phone, tap the **Workspace** tab at the bottom of the screen, then **Members**, and tap the person's row to pick a role. The owner's row can't be changed.

## Good to know

- **Editing a scheduled post unschedules it.** Pressing **Edit** on a scheduled post turns it back into a draft. An owner or Admin schedules it again with **Schedule All**. An Editor has to submit it for approval again. See [Approvals](/docs/team/approvals/).
- **Hero_Agent follows your role.** It can't do anything your role can't. For an Editor it creates drafts and can send them for approval; for a Viewer it chats and reads. See [Hero_Agent](/docs/ai/hero-agent/).
- **AI tools have their own permissions.** Only owners and Admins connect them, and each connection has its own settings. See [Links, permissions and activity](/docs/ai-tools/links-permissions-activity/).
- **Billing is personal.** Each person's Billing page shows their own plan. Admins can't see or change the owner's plan, invoices or payment details. Team members with no plan of their own see "Your plan is provided by your workspace owner."
- **Team → Permissions** is a short summary of the Admin, Editor and Viewer roles, for reference. It has no settings, and roles can't be customized. The table above is the full list.
- **Buttons can take a moment to appear.** When a page opens, Heropost checks your role first, then shows the buttons your role allows.
- **Roles need the owner's plan to include a team.** See [Team seats on each plan](/docs/team/seats/).

## If it doesn't work

| What you see | What it means | What to do |
|---|---|---|
| A button is missing, such as **Schedule All**, **Delete** or **Add Profile** | Your role doesn't include it. | Ask the owner or an Admin to do it, or to change your role. |
| "Viewers cannot create or modify content in this workspace." | Viewers can't create or change posts, files, captions or post groups. | Ask for the Editor role. |
| "Viewers cannot submit posts for approval." | Only Editors submit posts. | Ask for the Editor role. |
| "Only the workspace owner or an admin can perform this action." | For example, deleting a draft, or taking someone else's post out of review. | Ask the owner or an Admin. |
| "You don't have permission to manage team members." | Only owners and Admins invite, change roles or remove people. | Ask the owner or an Admin. |
| "You don't have permission to manage this account." | Only owners and Admins can remove or change social accounts. | Ask the owner or an Admin. |
| "You don't have permission to review approvals." | Only owners and Admins approve or reject posts. | Ask the owner or an Admin. |
| "No automations yet. An owner or admin can set these up for this workspace." (on a phone) | Editors and Viewers can't set up automations. | Ask the owner or an Admin. |
| "Access denied to this workspace." | You aren't a member of this workspace any more. | Ask the owner to invite you again. |

## Questions

**Can I create my own roles, or change what a role can do?**

No. The four roles are fixed. Pick the one closest to what the person needs.


**Can an Editor publish without approval?**

Not from the post editor: Editors get **Submit for Approval** instead of **Publish All** and **Schedule All**, and **Publish now** is hidden for them. They can still drag a post that's already scheduled to another day or time on the calendar.


**Can I give someone access to only some of the social accounts?**

No. A role covers the whole workspace. Keep accounts that should stay apart in separate [workspaces](/docs/social-accounts/workspaces/), and invite people only to the ones they need.


**Can a Viewer answer comments and messages?**

Yes. Viewers can read and reply in the [Social Inbox](/docs/analytics/social-inbox/).


**Can a workspace have two owners?**

No. Make the second person an Admin.
