SIGBOT
Legal & Trust

Roles and permissions

Last updated: 9 September 2026

What each role in a Sigbot team can do, how folder grants apply inside shared folders, and the team-wide switches the owner controls.

1. Team roles

Every member of a team holds one of three roles. The role is set when you are invited and can be changed by the owner.

Owner

Holds every permission, including billing, seats and ownership transfer. There is one owner per team. The owner's permissions cannot be restricted.

Admin

Runs the team day to day. By default an admin holds every permission in the table in section 3. Billing stays with the owner.

Member

Works inside the shared folders they have been given access to. By default a member can add contacts to shared folders and holds no other team-wide permission.

Roles govern team-wide actions such as inviting people or exporting. What you can do inside a particular shared folder is governed by your folder grant, described next.

2. Folder grants

Inside a shared folder, each member holds one of four grants: viewer, editor, admin or owner. Grants are set per folder by a folder admin. A subfolder can narrow a grant but not widen it. Team owners and admins hold at least admin on every shared folder.

GrantWhat it allows
ViewerSee and search the folder's contacts.
EditorViewer, plus add contacts to the folder and remove them from it.
AdminEditor, plus edit the shared record, delete contacts to the folder's trash, manage columns and subfolders, and set other members' grants.
OwnerAdmin, plus transfer the folder to another member. The member who creates a folder is its owner.

3. Team permissions

These are the team-wide permissions, what each one allows, and whether each role holds it by default.

PermissionWhat it allowsOwnerAdminMember
Export contactsDownload shared folders as CSV, Excel, JSON or vCard.
Add to shared foldersShare own contacts into team folders and run scans in the team scope.
Invite peopleSend and revoke invitations (seats permitting).
Manage scan rulesExclude domains and addresses from the team's scans, and purge them.
View private contactsSee the full record of a contact another member marked private.
Manage integrationsConnect Zapier and API access for the team.

The owner always holds every permission and can change the admin and member defaults in Admin console → Settings → Permissions. The server checks the matrix on every call, so a permission that is off for your role cannot be reached by a client that ignores the setting. Billing is owner-only and cannot be granted to another role.

4. Team security policy

Two switches in Admin console → Settings apply to the whole team. Only the owner can change them.

Two-step verification for admins

When this is on, inviting people, removing them, changing roles, transferring ownership and changing seats all need a sign-in that used an authenticator code. The owner must turn on two-step verification for their own account first (Account details → Security) and sign in again with a code before switching it on, so nobody is locked out.

AI parsing for team scans

When this is off, scans run in the team scope use Sigbot's built-in parser only, and nothing from a connected inbox leaves the platform. A team-scoped scan uses AI only when both this switch and the scanning member's own setting (Account details → Privacy) are on. Our Privacy Policy describes what is sent when it is on.

5. Scan rules

Scan rules are a list of email addresses and domains that a scan treats differently. A member whose role has Manage scan rules keeps the team's list from the Admin console; it applies to every scan run in the team scope.

Personal accounts have the same list under Import Emails → Scan rules; it applies to your own scans.

6. Private contacts

Any member can mark one of their contacts private. In shared folders, teammates then see a row labelled "Hidden contact" with no name, email address or other details, so they know a record exists and can ask about it. A member whose role has View private contacts sees the full record, as does the member who owns it.

7. Where this is enforced

Every team action goes through Sigbot's servers, which check the caller's role, folder grant, permission set and the team's security policy before acting. Team actions such as invitations, role changes, exports and permission changes are recorded in the team's audit log. The controls on this page form part of the measures described in our Security Overview and Data Processing Addendum.

8. Contact

Questions about roles and permissions: support@sigbot.co. Security questions: security@sigbot.co.