Task

Give teammates the right access

Combine safe starting profiles with reusable access bundles without handing over ownership or provider administration.

Applies to V1.2+ · Checked July 2026

Before you start

  • Owner or Administrator access
  • At least one teammate

Give teammates the right access

Cygnetree separates a person's workspace membership from the work they may perform. Start with a clear built-in profile, then add reusable access bundles when your team does not fit a single job title. Profiles and bundles control access; they are not pricing tiers.

Start with a built-in profile

Open Settings, find the teammate, and expand Change profiles.

  • Owner controls ownership and the complete workspace lifecycle.
  • Administrator runs the workspace, team, integrations, work, and money.
  • Manager runs client work and automations without changing the team or integrations.
  • Team member handles everyday client and project work without money or administration.
  • Assigned-project contractor receives only explicitly assigned project access.
  • Bookkeeper works with invoices, payments, financial reports, and exports.

You can combine focused profiles—for example, Team member and Bookkeeper. Cygnetree grants the union of both profiles. Choose the least access that lets the person complete their work.

Create a reusable access bundle

In Settings → Invite a teammate → Reusable access bundles, choose Create access bundle. Give the bundle a recognizable job-oriented name, explain when it should be used, and select its operational permissions.

A bundle can cover people, projects, documents, scheduling, communications, automations, money, exports, and reports. Keep bundles focused. “Field coordinator” is easier to review later than “Extra access.”

Combine access for a teammate

Find the teammate, expand Reusable access bundles, select every applicable bundle, and save. The new effective access is the union of the person's built-in profiles and active bundles. Overlapping permissions do not grant anything twice.

Bundles belong only to this workspace. Assigning one does not affect the person's access in another business they use with the same account.

Change or remove access safely

Clear a bundle from a teammate and save to remove those grants. Archive a bundle when nobody should receive it again. Archiving takes effect immediately for every assignment but preserves the history needed to understand past access.

Suspension, removal, ownership transfer, and built-in profile changes remain separate deliberate actions. The Membership history section records these lifecycle changes and access-bundle changes.

Choose how routine updates arrive

In Settings → My notifications, choose which kinds of workspace updates you receive and when routine email updates should arrive.

  • Immediate sends routine updates as they happen.
  • Daily digest combines routine updates at your chosen local time.
  • Weekly digest combines routine updates on your chosen day and local time.

Set your timezone before choosing a digest time. You can also enable quiet hours to hold routine immediate updates until the quiet period ends. Overnight windows such as 9:00 PM–8:00 AM are supported.

System and security notices always arrive immediately. Client and vendor communication preferences are separate from teammate delivery settings. If your workspace has selected its own email provider, Cygnetree uses that provider and will not silently switch identities after a failure.

Browser alerts use separate inquiry, client activity, scheduling, task, and business category switches. Enable the current browser deliberately, then choose the categories for this workspace; changing them does not change email delivery. Routine browser alerts use the same quiet hours, while system and security alerts remain immediate. One browser subscription follows your identity, but every alert is authorized and routed against the workspace that produced it.

Understand protected administration

Custom bundles cannot grant workspace administration, team administration, integration administration, ownership, platform-support access, or client/vendor portal identity. Those boundaries cannot be bypassed by naming a bundle “Administrator.”

Client and vendor access is configured on the relevant project and portal invitation. It never inherits a workspace teammate's bundles.

Verify access before relying on it

After changing access, have the teammate sign in again and check their home page, navigation, project list, global search, communications, reports, and any vendor collaboration they operate. Archive one test bundle and confirm its granted features disappear while the person's membership remains active.

If an allowed page is missing, first check both the built-in profiles and assigned bundles. Then confirm that the feature itself is enabled for the workspace; enabling a product feature and granting a teammate permission are separate decisions.

Keep going

Did this guide get you unstuck?

If not, tell us — this opens a support conversation with the guide already attached, and a real person reads it. If the guide is wrong or missing something, we fix the guide.

Tell us what's missing