Roles and permissions
What Viewers, Operators, and Admins can each do in a workspace.
Every member of a workspace has one of three roles. Roles are hierarchical — each one includes everything the role below it can do.
The three roles
| Role | Can do | | --- | --- | | Viewer | Read-only access — view duplicates and workspace data. | | Operator | Everything a Viewer can, plus approve/reject and execute merges, and manage workspace data. | | Admin | Full access — everything above, plus manage members and all settings. |
What each role sees
Some features are gated by role:
- Viewers can browse duplicates, clusters, and history, but can't act on them.
- Operators can review and merge, manage matching rules and false positives, and set up scan schedules.
- Admins additionally control workspace settings, the Detection cockpit, live monitoring, and team membership.
When you don't have access to something, DeDupe tells you — often with a note like "Ask a workspace admin" — rather than hiding why.
Changing a role
Admins change roles from Settings → Workspace → Team members. Note that you can only assign Viewer or Operator there; see Invite and manage teammates.