Roles and permissions deep dive

The four built-in roles, the nine permission modules, record scopes, and recipes for custom roles.

Access in K3X is controlled by roles. Four ship out of the box, and you can create custom roles when those don't fit.

The built-in roles

  • Owner — full control, locked. Owners can't be demoted, disabled, or removed by anyone else; only K3X support can transfer ownership today.

  • Administrator — full permissions; the role itself is editable.

  • Sales Manager — broader scope than a rep: sees and acts across the team's records.

  • Sales Representative — the default for invited reps: sees and acts on records assigned to them.

How a role is defined

Each role is a set of toggles across nine modules — records, deals, pipelines, emails, calls, SMS, agents, analytics, and settings — plus a record-scope choice: all records or assigned only.

That scope choice is the one that surprises people: a rep with "assigned only" sees their slice of every tab, not the whole team's. If someone reports "leads are missing," check their role's scope first.

Custom roles

Create them from Settings → Roles. Recipes teams actually use:

  • Read-only analyst — records and analytics on, all write toggles off, scope: all records.

  • SDR — records, emails, SMS, calls on; deals and settings off; scope: assigned only.

  • Ops/admin without billing — everything except settings.

Changing and managing

  • Change a member's role from the active member's drawer — takes effect on their next request.

  • Disable a member for an instant, reversible access cut (audit trail preserved).

  • Delete to remove them from the org (they keep their personal K3X account).

  • Non-owners can leave on their own from Settings → Membership.

Related controls

Analytics is a permission-gated tab — if someone can't see it, their role doesn't include it. Call recording access is also per-role (Settings → Roles → [role] → Voice → Record calls).

Did this answer your question?
😞
😐
😁