Choose the role by responsibility
Use the least-privileged role that still lets the person complete their assigned support work.
- Organization owners can manage billing, organization-wide requests, team access, channels, knowledge, and support decisions.
- Organization administrators can manage team access, channels, knowledge, and organization configuration without owner-only billing authority.
- Reviewers can review and send replies but do not manage organization configuration.
- Read-only members can inspect the workspace without reviewing or sending customer replies.
Revoke access promptly
Changing or removing membership is the organization access control. A remembered workspace cookie does not override the server-side membership check.
- Open Team from the affected organization.
- Confirm the member email and current role.
- Revoke or remove the membership.
- Verify that the user can no longer open the organization's routes or data.
Keep managed support separate
AppsResolve managed-service access is not a hidden customer-team role. It uses explicit assignments or time-limited, audited support sessions with a recorded reason and scope. The customer workspace role list should continue to represent the customer's own team.
