Every member holds one role per workspace. Use the three built-in roles, build your own from 58 permissions across 19 categories, or let your identity provider decide who gets what.
Every member of a workspace holds exactly one role in it. The role carries a set of permissions, and those permissions decide what the member can see and do. Somebody who belongs to two workspaces holds a separate role in each.
Roles live under Admin → Security → Roles & Permissions. The permissions themselves are fixed by whoot. — you cannot invent a new one — but you can combine them into as many roles as your organisation needs.
Three roles ship with every workspace. They cannot be edited or deleted, but you can duplicate one as the starting point for your own.
The default for everyone who is not an administrator. Can use the rooms they are assigned to, start a peer-to-peer call from the directory, play back their own recordings, see their own analytics, and raise a support ticket. No access to the admin dashboard at all.
Holds every permission in the workspace, including the ones that end it. Every workspace needs at least one — see The Last Administrator below.
A read-only role used only by the temporary cross-organisation access flow. It is applied automatically when an access request is approved and removed when the grant expires. Do not assign it by hand.
Permissions are grouped by the part of the product they govern, and ordered within each group from viewing, through configuring, to destroying. Two tiers carry a marker:
The role list shows how many critical permissions each role carries, so you can see at a glance which roles deserve a closer look.
You can also work role-first. Admin → Security → Roles & Permissions → ⋯ → Manage Users lists everyone currently on a role and lets you add or remove members from there.
A role can only be assigned by somebody who already holds every permission it grants. That stops a delegated user-manager promoting themselves to full administrator.
Every assignment, and every change to a role's permission set, is written to the audit log with a before-and-after record.
A workspace can never be left with nobody able to assign roles. The permission that matters is Change user roles: it is the only route back, because nobody can grant a permission they do not already hold themselves.
whoot. therefore refuses any action that would remove the last member holding it — demoting yourself, deleting the role that carries it, editing that permission out of the role, or removing the member. You will get a message explaining the fix: give somebody else a role that includes Change user roles first.
If you run Entra ID, Okta, or another identity provider, you can map its groups to whoot. roles instead of assigning them by hand. Members of your "Security Leads" group become administrators automatically, and stop being administrators when they leave it.
Roles govern the workspace. Whether a member may transmit in a particular room is separate, and set per room on the member's Rooms list under Admin → Application → Users, using the TX Permission toggle.
That lets you run a room where a small group speaks and everybody else listens, without giving anyone a different workspace role.