User Roles and Permissions
This article outlines Accord’s roles and permissions settings for users and AI agents.
Table of Contents
Solution Providers vs. Customers
Solution Providers: The team who owns the Accord workspace (you!) Typically sales, customer success, solution engineers, or other customer facing roles.
Customers: Any external member you add to an Accord.
Roles and Permissions in Accord
In earlier versions of Accord, a Solution Provider user could only be assigned as an Admin or a User. For organizations requiring more flexibility a new roles and permissions system is now included in Accord.
A role is the term used for a named set of permissions. Every workspace starts with two new built-in roles Workspace Admin and Member (replacing the prior Admin and User) with the ability to add more from a list of presets, or (for enterprise customers) the ability to fully customize and create new roles. Someone can be assigned multiple roles at once, with the ability to perform the sum of everything their roles allows.
Customers are not impacted by the new roles and permissions system and retain the previous list of permissions granted to them. See here for a list of actions that can be performed by Customers.
Note: Workspace Admins retain full access and you can’t reduce the actions a Workspace Admin can perform in Accord. An Accord workspace will never allow you to have less than one Workspace Admin.
Configuring Roles and Permissions
The new roles and permissions system replaces the original system and is enabled by default for all workspaces. If you are a workspace admin (Checking your role in Accord) and do not have access to the “permissions” tab under settings please contact your Accord Customer Success Manager.
Workspace Admins can manage the available roles for their organization in:
Settings → Permissions
The permissions page shows a grid with one row per permission and one column per role. Every permission has a description highlighting exactly which behaviour is allowed or restricted.

What Your Plan Includes
Depending on your Accord Plan, the available functionality of the roles and permissions system differs:
All Workspaces: All Accord workspaces are able to view the roles and permissions grid, create roles from an existing template, rename roles, and assign roles to users.
Enterprise Workspaces + Accord Agent Customers: In addition to features inherited by all workspaces, Enterprise workspaces can fully customize their roles and permissions, turning individual permissions on and off. Enterprise workspaces (and Accord Agent customers) also have access to an additional “MCP” tab that allows full control over what actions AI agents can perform via MCP.
Creating a Role
To create a new role, from the permissions page workspace admins can click “Add Role”. Every new role starts from an existing template, so you never begin with an empty column.
- In Settings → Permissions, click Add Role
- Enter a Role Name
- Choose a template under Start from preset
- Click Add Role
The new roles will appear as its own column, seeded with that template’s permissions.

Note: Only Enterprise customers can fully customize these templates. Non-enterprise users may rename roles but must select from one of the following starting templates.
Accord currently provides four templates.
Preset Roles (All Workspaces)
All workspaces ship with the following role templates by default:
|
Template |
Starting Permissions |
|
Member |
Day-to-day rep access: create, edit, publish and archive Accords, add members and placeholders, use published playbooks, attach library resources, view and export reports, update CRM fields from inside an Accord. |
|
Workspace Admin |
Everything, including workspace settings, playbooks, library content, teams, API keys, and CRM connections. |
|
Playbook Admin |
The Member baseline plus building playbooks, execution criteria, condition types and section types. No library resource management, workspace settings, or CRM connections. |
|
CMS Admin |
The Member baseline plus managing library resources, steps, stages, hubs and tags. No playbooks, workspace settings, or CRM connections. |
Assign Roles to Members
Roles are assigned to users in Settings → Members. Open the role dropdown on each user's row to add or remove roles, and use the role filter above the table to see everyone who holds a particular role.
When assigning roles the following rules are always enforced by Accord:
- Everyone keeps at least one role, so removing someone's last role is blocked.
- Your workspace keeps at least one Workspace Admin.
- You can't change your own roles. Ask another admin.
- Buyer-side members on your Accords can't be given Workspace Admin.

API Keys
Just like users, API keys are also assigned a role in Accord. When you create an API key you pick the role it acts as, and a key inherits the permissions of that role.

Note: Neither the role nor the settings can be changed after the key is created, so issue a new key rather than trying to edit an old one.
Editing Roles (Enterprise Only)
The roles and permissions grid is grouped into six sections you can expand and collapse independently: Accords, Playbooks, Library, Reports , CRM (section takes the name of whichever CRM you've connected to), and Workspace.
Each row is a permission with a short description underneath. However, one row can cover several underlying actions. In this instance hover over a row description to see a list of exactly what actions it includes.

Use Search permissions to find a row by its name or description. Matching sections open automatically, so a result is never hidden behind a collapsed header.
To change what a role can do:
1. Open Settings → Permissions
2. Find the permission row you wish to change
3. Tick or untick the cell where that row meets the role's column.
Note: There's no save button. Each cell saves as you click it, and reverts with a message if the change doesn't go through.
Workspace Admin is locked
The Workspace Admin's column can't be edited and has the highest level of permissions. Reducing it can result in locking out a workspace out of its own settings.
However, you can scope what an agent acting as a Workspace Admin is allowed to do, via the MCP tab.
Scoping AI Agents Using the MCP Tab (Enterprise)
Note: MCP Write access is currently in beta with plans to release for Enterprise workspaces and Accord Agent customers in September 2026.
The toggle above the permissions grid switches between User permissions and MCP permissions.

User is what a person can do when they're working in Accord themselves. MCP is what AI agents can do on your workspace's behalf. Grant permissions only if you're comfortable with an agent performing it without a person in the loop.
Agent access can never exceed a person's own access. If a role can't do something in User mode, granting it in MCP mode has no effect, and revoking a permission in User mode revokes it for agents too.
See For more information on the Accord MCP server please see the following articles
Resetting and Deleting Roles
Click the pencil icon at the top of a role's column to rename, reset or delete it.
![]()
Reset puts a role back to its starting point and discards your changes. For Workspace Admin and Member it reads Reset to defaults, since their starting point is Accord's built-in default. For a role you created it reads Reset to template, meaning the starting template you chose in Add Role.
Delete Role is available on roles you created. A role that's still assigned to users can't be deleted either; the modal tells you how many members hold it so you can reassign them first.
Checking your role in Accord
Anyone can see their own roles on their profile page, under Your Roles: the roles assigned to you in this workspace, which determine what you can see and do. It's the quickest answer to "why can't I edit this?", and it saves a round trip to an admin.
Customer Permissions
The following outlines the permissions available for Customer users in Accord.
| Customer | ||
| Accord Settings | Share Accord | ✓ |
| Summary Page |
Edit Summary Page | ✓ |
| Add/Delete Section | ✓ | |
| Next Steps Page | Edit Stage | ✓ |
| Copy Stage URL | ✓ | |
| Delete Stage | ✓ | |
| Duplicate Stage | ✓ | |
| Filter By Step Owner | ✓ | |
| Hide Completed Steps | ✓ | |
| Assign Step Owner | ✓ | |
| Assigned Step Due Date | ✓ | |
| Select Step Type (Task, Meeting, or Approval) | ✓ | |
| Assign Step Stakeholders | ✓ | |
| Agenda Items to Step | ✓ | |
| Add Resources to Step | ✓ | |
| Comment on Steps | ✓ | |
| Copy Step URL | ✓ | |
| Delete Step | ✓ | |
| Duplicate Step | ✓ | |
| Resource Page | Add New Folder | ✓ |
| Add New Resource | ✓ | |
| Connect a Step | ✓ | |
| Pin Resource | ✓ | |
| Copy Resource URL | ✓ | |
| Edit Resource | ✓ | |
| Delete Resource | ✓ | |
| Team Page | Add Member (SP) | ✓ |
| Add Member (CU) / Assign Placeholder (CU) | ✓ | |
| Resend Invite | ✓ | |
| Workspace Settings | Edit Profile (Name, Job Title, Phone Number Meeting URL, LinkedIn URL) | ✓ |
| Edit Notifications (General / Accords) | ✓ | |
Troubleshooting
The permission checkmarks are visible but greyed out.
Editing individual checkmarks is an Enterprise capability. For non-enterprise customers You can still create roles from a template, rename them, reset them and assign them.
You can't change your own roles.
This is deliberate, so nobody can quietly grant themselves more access or drop their own. Another admin can make the change.
A role won't delete.
Roles that are still assigned can't be deleted, because deleting one would silently change what those people can do. Reassign them first before deleting. Built-in roles can't be deleted at all.
Reset isn't offered on an older role.
Roles created before Accord started recording which template they came from have nothing to reset to. Create a fresh role from the template you want and reassign members to it.
A buyer-side member can't be made a Workspace Admin.
Workspace Admin is for your own team. Buyer-side members on an Accord are never eligible, regardless of the roles you've built.