Access in K3X is controlled by roles. Four ship out of the box, and you can create custom roles when those don't fit.
The built-in roles
Owner — full control, locked. Owners can't be demoted, disabled, or removed by anyone else; only K3X support can transfer ownership today.
Administrator — full permissions; the role itself is editable.
Sales Manager — broader scope than a rep: sees and acts across the team's records.
Sales Representative — the default for invited reps: sees and acts on records assigned to them.
How a role is defined
Each role is a set of toggles across nine modules — records, deals, pipelines, emails, calls, SMS, agents, analytics, and settings — plus a record-scope choice: all records or assigned only.
That scope choice is the one that surprises people: a rep with "assigned only" sees their slice of every tab, not the whole team's. If someone reports "leads are missing," check their role's scope first.
Custom roles
Create them from Settings → Roles. Recipes teams actually use:
Read-only analyst — records and analytics on, all write toggles off, scope: all records.
SDR — records, emails, SMS, calls on; deals and settings off; scope: assigned only.
Ops/admin without billing — everything except settings.
Changing and managing
Change a member's role from the active member's drawer — takes effect on their next request.
Disable a member for an instant, reversible access cut (audit trail preserved).
Delete to remove them from the org (they keep their personal K3X account).
Non-owners can leave on their own from Settings → Membership.
Related controls
Analytics is a permission-gated tab — if someone can't see it, their role doesn't include it. Call recording access is also per-role (Settings → Roles → [role] → Voice → Record calls).
