Last updated July 27, 2026
Section 1.4: Team Management & Permissions
Managing a production team or agency workspace requires clear roles, access control, and granular permissions. The Team tab on your organization dashboard is the central workspace for adding members, assigning roles, and configuring access.
1. Workspace Roles
ABRAM Network offers three main administrative roles to organize your workspace:
- Owner: The primary workspace creator. Has complete control over the organization, including billing, custom roles, permissions, and the ability to delete or transfer the workspace.
- Admin: Full administrative permissions to manage team members, invite new users, configure equipment logistics, and modify all projects. Admins cannot delete the organization or modify the Primary Owner's role.
- Member: Standard production staff or crew access. A Member's access to billing, invoicing, logistics, and specific projects is entirely controlled by their assigned Granular Permissions.
2. Plan Tiers and Seat Limits
Team-management capabilities and the number of seats available depend on your organization's plan:
| Plan | Seats |
|---|---|
| Team | 2–5 |
| Studio | 6–20 |
| Enterprise | Unlimited |
Multi-seat collaboration and role-based member permissions require a Team plan or higher. Solo-tier plans include a single seat and don't expose multi-member role and permission management.
3. Granular Permissions (Admin & Member Settings)
Administrators can customize the access level for any individual Admin or Member to match their department duties. Open the Edit Team Member modal on any user to adjust these toggles:
- Team Management: Allows the user to invite new team members, edit member details, remove members, or adjust their permissions.
- Financial Access: Allows the user to view project budgets, freelancer/crew rates, company expenses, and invoices.
- Org Profile Management: Allows editing the organization's public profile (uploading company banners, changing logos, editing the bio, and managing highlights).
- Resource Management: Allows the user to manage equipment inventory, condition logs, storage locations, and schedule equipment logistics.
- Financial Management: Allows the user to create, edit, and cancel invoices for their projects.
- Internal Project Requests: Allows the user to configure the project request intake form and manage the submissions inbox.
- Postings Management: Note: Only visible and active when the platform is switched to the Marketplace Phase. Allows creating, editing, and publishing job opportunity postings to the external network.
- Discover Page Access: Note: Only visible and active when the platform is switched to the Marketplace Phase. Allows browsing and searching the external talent network on the Discover page.
- Project Access Settings:
- Manage All Organization Projects: The member can view, create, edit, and manage team access for all projects in the organization.
- Assigned Projects Only: The member is restricted strictly to projects they are explicitly added to. They can view project details and add or check off deliverables.
4. Custom Roles (Enterprise Plans)
On an Enterprise plan, administrators can go beyond the standard Admin and Member roles by creating Custom Roles. Each custom role has:
- A name and a short description so other admins understand its intent.
- Its own set of permission toggles, configured the same way as the granular permissions above.
Once created, a custom role can be assigned to any member from the Edit Team Member modal, giving that person a tailored permission set without making them a full Admin.
5. Inviting Team Members
- Navigate to the Team tab.
- Click Invite.
- Enter the invitee's First Name, Last Name, and Email, then choose their Role (Admin or Member).
- Send the invitation. The user will receive an email containing a link with an invitation token. Once they log in, they are automatically joined to your organization.
Department, custom role assignment, and rate information are not collected at invite time — those are configured afterward from the member's profile (see Editing a Team Member below).
Bulk Invite: To add several people at once, use the Bulk Invite option instead of inviting members one at a time.
Seat limits: If your organization is already at its plan's seat capacity, you'll see a seat-limit prompt when trying to invite a new member. Free up a seat or upgrade your plan to continue.
6. Editing a Team Member
Opening the Edit Team Member modal on any user exposes:
- Their Role (Owner, Admin, or Member).
- An optional Custom Role assignment (Enterprise plans — see above).
- Granular permission toggles (see Granular Permissions above).
- An HR panel covering:
- Title — e.g., "Director of Photography", "Production Manager".
- Department — e.g., "Post-Production".
- Division
- Employee Number
- Employee Type — e.g., Employee, Freelancer, Contractor, Intern, Consultant.
- Level
- Reports To — manager mapping.
- Hourly Rate — only visible to users with Financial Access permissions.
- Years Experience
- Availability — e.g., Available (Bench), Assigned to Project, or Unavailable. This helps scheduling coordinators filter available staff.
- Weekly Capacity
Visibility Overrides
- Show on Company Profile: Set whether to display this team member in your organization's public member directory.
- Allow Public Profile: Toggle whether to permit this employee to publish an individual public freelancer profile on the network.
7. Enterprise SSO & Directory Sync (Enterprise Tier Only)
Enterprise workspaces can configure corporate Single Sign-On (SSO) and automatic directory sync to manage member authentication and accounts:
- Tier Gating: SSO and directory sync features are exclusive to the Enterprise plan tier. Self-service settings for these features are locked by default in the Organization Settings tab under Enterprise Authentication.
- Setup Activation: To configure these settings, the organization owner must contact support to coordinate with your IT administrator. Once domain verification is complete, configuration controls will unlock in the settings tab.
- Directory Control: When directory sync is active, team member rosters, account activation status, and role mappings are driven entirely by your corporate identity provider (e.g., Okta, Microsoft Entra ID).
- Local Read-Only Lock: For members added via directory sync, their identity and organization-hierarchy fields (name, role, organization membership, Department, Division, Employee Number, Employee Type, and Reports To) are read-only in ABRAM — any updates must be made in the corporate identity provider dashboard and will reflect in ABRAM automatically. Hourly Rate and the visibility toggles ("Show on Company Profile", "Allow Public Profile") remain editable locally even for directory-synced members.
8. Audit Logs (Enterprise)
On an Enterprise plan, organization admins can review an Audit Log of member and security-related activity — such as role changes, permission updates, and sign-in events — to support internal oversight and compliance needs.