<!--
  Translated by the docs agent from content-src/es/guides/equipo-roles/03-la-matriz-de-roles-que-puede-hacer-cada-uno.md
  (source_hash 7f071ae0fd68). If that Spanish source_hash changes, re-check this translation.
-->

| Role | What it can do |
| --- | --- |
| **Admin** | Everything: billing, team, agents, channels, settings — including the Danger zone (deleting the account). |
| **Editor** | Day-to-day operations — conversations (including taking control), leads, knowledge base, document templates, and contacts and marketing (Manual 27 · Marketing) — without configuring agents, channels, billing or team. |
| **Read-only (viewer)** | Can view conversations, leads and analytics, but doesn't write or change anything on any screen. |

There's no separate "owner" role: the **Admin** role is the tenant's top one, and it also includes the most
sensitive actions, such as deleting the account (Manual 26 · Settings and integrations).

## 3.1. Detail by area

| Area / screen | Admin | Editor | Read-only |
| --- | --- | --- | --- |
| Billing | Yes | No | No |
| Team (invite, change roles) | Yes | No | No |
| AI agents | Yes | No | No |
| Channels | Yes | No | No |
| Settings (including Danger zone) | Yes | No | No |
| Conversations (inbox, including taking control) | Yes | Yes | View only |
| Leads | Yes | Yes | View only |
| Analytics | Yes | Yes | View only |
| Knowledge base | Yes | Yes | — |
| Document templates | Yes | Yes | — |
| Contacts and Marketing (Manual 27) | Yes | Yes | View only |

Cells with "—" are areas for which this manual's source doesn't detail Read-only's exact access beyond its
general rule: "can view, but doesn't write or change anything."

> **Note — Support follows a separate pattern**
>
> **Support** tickets with your provider's team (different from the internal Contacts and Marketing
> tickets) can only be created, seen and replied to by Admins: the other roles see the screen with the
> "Administrators only" notice. Full detail in **Manual 28 · Support**.

> **Warning — The interface hides, but the system decides**
>
> Even though the interface hides an option from someone who doesn't have the role to use it, the
> permission decision is always controlled by the system: if someone tries something they don't have
> permission for, it's rejected with a clear notice, even if they'd managed to reach that screen through
> another route.