The five roles
In the product’s data the Analyst role is called
viewer. You may see that name in exports or support conversations.What each role can do
Approval tiers
Every proposed action carries a blast-radius tier from B0 to B4. The tier sets how senior the approver must be.
When a proposal is above your tier, the review panel tells you it “is above your access — this routes to” the role that can approve it. Analysts see exactly why Hive proposed something, but only Operators and above can act. See Autonomy and blast radius for how tiers interact with autonomy.
Department scope
Owners and Admins always see the whole business. Hive’s role model also has department scope for Department leads, Operators and Analysts (Finance, Sales, Marketing, Customer Success, People, IT & Security), but you can’t choose a member’s departments yet: invites don’t ask for them, and nobody can switch departments.Preview a role
On a workspace that shows sample data (no identity provider connected), Owners and Admins can preview the product as another role from Roles & access with Preview as …. A banner reads “Previewing as …” while the preview is on, and Exit preview returns you to your own view. Use it to check what a new Analyst will actually see. Signed-in workspaces do not offer preview, because a local preview would not reflect real permissions.Connectors and roles
Connectors use a two-step model:- An Owner or Admin enables a provider for the workspace. Connecting it yourself as an admin enables it automatically.
- Any member can then connect their own account for that provider. Until a provider is enabled, members see “A workspace administrator must enable this provider before you can connect a personal account.”
Workflows and agents: per-item access
Workspace roles decide whether someone can run or build. Each workflow and agent also has its own sharing:
Running still requires the Operator role or above. Admins and Owners can read every workflow and agent in the workspace, even ones not shared with them, but cannot run or edit one they have not been given access to. See Share and reuse.
Rules that protect the workspace
- No self-edit — you cannot change your own role.
- No escalation — you cannot grant a role higher than your own.
- Last Owner — the final Owner cannot be demoted or removed.
- Fail closed — if Hive cannot confirm your role, you get the most restrictive view, not the most permissive.
Frequently asked
Who should be an Owner?
Who should be an Owner?
Keep Owners to the people accountable for the business — usually one or two. Owners and Admins share almost every capability, so most administrators should be Admins.
Can an Operator edit the Business Brain?
Can an Operator edit the Business Brain?
Operators can pause learned behaviours and work with the knowledge Hive holds. Activating a proposed behaviour so Hive uses it needs a Department lead, Admin or Owner. See Learned behaviours.
Can I create a custom role?
Can I create a custom role?
Not today. Hive uses the five fixed roles above, combined with department scope and per-item sharing.
Related
Team and workspace
Invite, change and remove members.
Review and approve
How approvals work in practice.
Safety and control
Policy, kill switch and spend caps.
Security overview
How Hive enforces access behind the scenes.