> Lettrove docs 1.x · https://docs.lettrove.com/docs/app/team

# Workspaces, roles and the activity log

## Workspaces

A **workspace** is one team's Lettrove: its emails, templates, brand, audiences, sending domains,
integrations and members. A person can belong to several and switches between them; everything is
kept per workspace, and nothing crosses between them. The person who creates a workspace is its
**owner**.

## Roles

Every member has one role. Permissions are deny-by-default: a role can do exactly what is listed,
and the check reads your live membership, so a change takes effect at once.

| | Viewer | Editor | Admin | Owner |
|---|---|---|---|---|
| View emails and templates | ✓ | ✓ | ✓ | ✓ |
| Create, edit, delete and mark emails ready | | ✓ | ✓ | ✓ |
| Upload and delete images | | ✓ | ✓ | ✓ |
| Send test emails | | ✓ | ✓ | ✓ |
| View contacts and lists | | ✓ | ✓ | ✓ |
| Import, edit and sync lists | | | ✓ | ✓ |
| Send campaigns | | | ✓ | ✓ |
| Set up sending domains and sender addresses | | | ✓ | ✓ |
| Manage the brand kit | | | ✓ | ✓ |
| Connect integrations | | | ✓ | ✓ |
| Manage embed projects and their keys | | | ✓ | ✓ |
| Invite and remove people, change roles | | | ✓ | ✓ |
| Change workspace settings | | | ✓ | ✓ |
| Read the activity log | | | ✓ | ✓ |
| Manage billing | | | | ✓ |
| Transfer ownership, delete the workspace | | | | ✓ |

In one line each, as the invite screen puts it:

- **Viewer**: can look at emails and templates. Changes nothing.
- **Editor**: builds and sends test emails. Cannot invite people or change workspace settings.
- **Admin**: everything an editor does, plus inviting people, settings, campaigns and the activity log.
- **Owner**: full control, including billing, deleting the workspace and transferring ownership.

The same roles gate the [MCP server](/docs/app/mcp): an assistant connected as you can do what you
can, never more.

## Inviting people

**Settings → Members → Invite.** The invitation names the role, and the screen says in words what
that role can do. An invitation can be revoked until it is accepted; a member can be removed, or
leave, at any time, and loses access at once.

## The activity log

Every action that matters is written to an append-only log: sign-ins and failed sign-ins, password
changes, invitations, role changes and removals, emails created, deleted and restored, images
uploaded, brand changes, test sends and campaigns, integrations connected and removed, sources
synced and purged, embed projects and keys. Each entry names who did it, when, and to what.

Admins and owners read it under **Settings → Activity**, page by page.

## Connected apps

**Settings → Profile → Connected apps** lists the apps you have allowed to work as you (an AI
assistant through the MCP server, say), with what each was granted. **Disconnect** refuses the app
at its next token refresh; it has to ask you again.

## Your account

**Settings → Security**: change your password, and turn on two-factor authentication. Passwords are
hashed; sign-in, verification and invitation tokens are stored hashed, single-use and expiring.
