Team

Team Management and Access Control in Workspace

Team is a structure that Fyno built for you to work and collaborate effortlessly with your colleagues / teammates. But in order to understand how the Team function works, we will first need to understand what a Workspace is and how that functions. Read more here. The structuring and functioning of a Team works based on roles and policies assigned to each team member.

On signing up and creating a new account with Fyno, your Default Workspace is created and the registered email ID becomes the Organisation Owner.

What you can do with Teams

Team(s) allow you to:

  • Provide restricted access to individual employees as per their role requirements.
  • Have a centralized view of the team members along with their access levels and details.
  • Collaborate easily with colleagues on projects and tasks within the Fyno application.

How Access Control Works

Access in Fyno is managed using two layers:

  • Roles (Base Access): Every user is assigned a role that defines their default level of access across the platform.

  • Add-On Policies (Additional Access): Add-on policies allow you to grant specific capabilities on top of a role. This helps avoid assigning broader roles when only limited additional access is required. This is optional and can be used only when additional permissions are needed.

Add-on policies can be assigned:

  • During user invitation.
  • While modifying an existing user.

Add-on policies are available for all roles except Auditor.

This enables flexible and controlled access management across teams.

Roles

The below roles with unique levels of access have been created so that you can assign relevant roles to each person, based on what they need to access.

Roles & Permissions

Feature / AccessOwnerSuper AdminWorkspace AdminDeveloperCampaign ManagerSupportAuditorDefault Role
Analytics and Logs
Dashboard and AnalyticsYesYesYesYesYesYesNoNo
Alarms and AnomaliesYesYesYesYesYesYesNoNo
LogsYesYesYesTest onlyYesYesYesisent & notification event logs onlyNo
Report DownloadYesYesYesTest onlyYesNoYesNo
Communication Orchestration
IntegrationsYesYesYesYesView onlyView onlyNoNo
TemplatesYesYesYesYesView onlyView onlyNoNo
ComponentsYesYesYesYesView onlyView onlyNoNo
RoutesYesYesYesYesView onlyView onlyNoNo
Notification EventsYesYesYesYesView onlyView onlyNoNo
CampaignsYesYesYesYesYesView onlyNoNo
User ProfilesYesYesYesTest onlyView onlyView onlyNoNo
User CohortsYesYesYesNoView onlyView onlyNoNo
User PreferencesYesYesYesYesView onlyView onlyNoNo
Workspace Settings
Invite Team MemberYesYesYesYesView onlyView onlyView onlyView only
API KeysYesYesYesYesView onlyView onlyNoNo
Allowlist (Webhooks)YesYesYesYesView onlyView onlyNoNo
Security SettingsYesYesView onlyView onlyView onlyView onlyNoNo
Delivery Limits (DND)YesYesYesYesView onlyView onlyNoNo
Add-onsYesYesYesiexcept push token cleanupYesiexcept push token cleanupView onlyView onlyNoNo
Workspace Creation / DeletionYesNoNoNoNoNoNoNo
Other Actions
Copy to another WorkspaceYesYesYesNoNoNoNoNo

Additional Notes

  • Owner, Super Admin, and Workspace Admin have broad access across most features and can perform high-level administrative actions.
  • Owner and Super Admin can unmask masked fields by default. For all other roles, unmasking requires the Unmask Sensitive Data add-on policy.
  • Each workspace can have only one Owner.
  • Only the Owner can add Super Admins, and any Super Admin added by the Owner will automatically be added to all workspaces under that Owner.
  • Certain permissions may vary by feature (for example, test-only access, view-only access, or restricted actions like Go Live / Fire), as detailed in the table above.

Restricting Access by Analytics Labels (Auditor only)

When you assign the Auditor role, you can further narrow what data that user is able to see by enabling Restrict to specific Analytics Labels.

  • The option appears only when the Auditor role is selected. It is not available for any other role.
  • When enabled, select the Analytics Labels the Auditor is allowed to access.
  • The restriction applies across all logs and reports available to that team member, based on their role.
  • The Auditor will only see data associated with the selected labels; data under all other labels remains hidden.

Note: This restriction narrows the data visible within the access the Auditor role already grants. It does not add any new access on its own.

Add-On Policies

Add-on policies provide fine-grained control over specific actions.

They are useful when a user needs limited administrative capabilities without being assigned a higher role.

The following add-on policies are available:

Add-On PolicyWhat it allows
Report DownloadDownload both test and live reports.
Unmask Sensitive DataUnmask masked fields in logs and download reports containing unmasked data.
Invite team members and modify rolesInvite, remove, and modify roles and add-on policies of team members.
ApproverView and approve modules that have approval enabled.

Note: Add-on policies can be assigned to all roles except Auditor. The Add-On Policy field is not available when the Auditor role is selected.

Report Download

This policy allows a user to download both test and live reports, regardless of the report access their base role provides.

This is useful when a user needs reporting access without being moved to a broader role.

Unmask Sensitive Data

This policy allows a user to:

  • Unmask masked fields in logs.
  • Download reports that contain unmasked data.

To unmask the details, navigate to the required record and click the eye icon.

Assign this policy only to users who are authorised to view sensitive customer data.

Invite Team Members and Modify Roles

This policy allows a user to:

  • Invite new team members
  • Remove users
  • Modify roles
  • Assign or update add-on policies

This is typically assigned to IT or operations teams responsible for onboarding and access management.

Approver

Users with the Approver policy can:

  • Access the Approval Requests page
  • View all requests assigned to them across modules
  • Review and take action (approve/reject) on those requests

They do not have direct access to modules, unless explicitly granted through another role.

Inviting and Viewing Team Members

To create a new team member, follow the below steps:

  1. From your Fyno account, click on the Workspace Settings icon from the bottom left side of the navigation menu.
  2. Navigate to the Team tab.
  3. Click + Invite Team Member.
  4. Enter the user’s Email ID.
  5. Select a Role based on the level of access required.
  6. Optionally attach Add-On Policy to the user. This option is not available for the Auditor role.
  7. If you selected the Auditor role, optionally enable Restrict to specific Analytics Labels and select the labels the user is allowed to access.
  8. Click Send Invite.

The newly invited colleague will receive an email with details to sign up on the Fyno application.

You can invite new members to collaborate within your workspace by following these steps.

Role Assignment Rules

  • Owner can assign any role.
  • Super Admin can assign Workspace Admin, Developer, Campaign Manager, Support, Auditor, or Default roles.
  • Workspace Admin can assign Developer, Campaign Manager, Support, Auditor, or Default roles.
  • Add-on policies can be assigned during invitation or updated later.

Modifying Roles and Add-on Policies

You can update a user’s role and policies after they have been added.

Note: These updates are permission- and role-specific, ensuring changes only affect the selected user’s access and do not impact other users or settings.

Steps:

  1. Navigate to Team from Workspace Settings.
  2. Locate the user in the list.
  3. Click the three-dot menu next to the user.
  4. Select Modify.
  5. Update the role and/or add-on policies. For users with the Auditor role, add-on policies are not available; you can update the Analytics Label restriction instead.
  6. Save the changes.

All role and permission updates are managed through the three-dot menu to ensure controlled access and avoid unintended changes.

Deleting a Team Member

To delete a team member from your workspace, follow the below steps:

  1. From your Fyno account, click on the Workspace Settings icon from the bottom left side of the navigation menu.
  2. Select Team.
  3. Click the three-dot menu next to the user.
  4. Select Delete.
  5. Confirm the action.

Note: This action is role- and permission-controlled. Only users with the appropriate permissions can delete team members, and this action is permanent.

Approval Settings

To enable Approval settings:

  1. From your Fyno account, click on Workspace Settings and navigate to the Team tab.
  2. Click Approval Settings.
  3. On the left-hand side, you will see a list of team members who have been assigned the Approver policy. At least one approver must be present to enable approval requests.
  4. On the right-hand side, enable approval requests for the required modules, such as:
    • Templates
    • Notification Events
    • Workflows
    • Routes
    • Campaigns

Once enabled, any changes made in the selected module will go live only after the assigned approver(s) approve the changes.

  1. Select the number of approvals required for each module. You can select up to 5 approvers.

For example, if 2 approvers are selected for Templates, any changes made to Templates will go live only after both approvers approve the changes.

  1. Click Save.

You can read more about it here

Important Pointers for your Reference

  • Roles define baseline access, while add-on permissions provide additional capabilities.
  • Certain actions, such as inviting users or modifying roles, require explicit permissions.
  • Features may be disabled or hidden if access is not granted.