Why all-or-nothing access breaks teams
Agencies are made of mixed groups. A couple of permanent people, a freelance designer on one project, a contract developer on another, a client-side stakeholder who wants to peek at progress. Most tools offer one distinction: admin, or not admin. That is not enough detail for how the work is actually staffed.
What happens next is predictable. Either you give a freelancer full access and quietly hope they never open the invoices, or you keep them out and start shuttling assets over email and chat. Both are worse than they look. The first is a real risk. The second guarantees the project's files and decisions end up somewhere nobody can find them later, which we covered in how to stop losing files in chat threads.
There is a subtler failure too: unclear ownership. If nobody can see who is assigned to what, the answer to “who has this?” becomes a message thread instead of a lookup.
What Arpixa Members is
Members is the access layer of your workspace. It holds your team, the role each person has, the permissions that role grants, and, where relevant, the specific projects they are scoped to. Two tabs split the work: Active Members and Pending Invites, each with a live count.
A role is not a label, it is a permission map. Assigning a role writes out access across all eighteen areas, and changing a role rewrites it. That means you never have to reason about a partially configured account: if someone is a Manager, you know exactly what they can reach.
What you can do in Members
| Capability | What it does |
|---|---|
| Five roles that match real agency shapes | Owner and Admin have full access. Manager runs projects, clients, proposals, docs, and files but no financials, invoices, analytics, or settings. Member works only on assigned projects. Viewer is read-only. You pick a role at invite time and can change it later from a dropdown on the member row. |
| Eighteen permission areas, four levels each | Permissions cover projects, clients, invoices, inbox, settings, analytics, automations, leads, proposals, docs, files, operations, archive, financials, calendar, wiki, forms, and the service catalog. Each is set to full, own, view, or none by the role, so access is explicit rather than implied. |
| Financial data is a separate switch | Revenue, invoices, payments, and profitability are gated by the financials permission, not bundled with project access. That is what makes it safe to give a producer or a freelancer real work access without opening the books. |
| Project-scoped access for contractors | The Member role sees only the projects assigned to it. An assignment panel lets you search, select, and bulk assign projects per person, and the team table flags anyone who needs assignments before they can see any work at all. |
| Invites you can fix and revoke | Invite by email address with an optional display name and a role. Pending invites can be re-sent, corrected when the address was mistyped, or revoked. Revoking an accepted invite removes workspace access on their next session. |
| A team table built for scanning | Active Members and Pending Invites are separate tabs with counts. Search by name or email, filter by role, and see each person with their role chip, assigned project count, and join or invite date, paginated so a large team stays readable. |
The five roles, side by side
| Role | Projects | Clients | Financials & invoices | Settings |
|---|---|---|---|---|
| Owner | Full | Full | Full | Full |
| Admin | Full | Full | Full | Full |
| Manager | Full | Full | None | None |
| Member | Assigned only | None | None | None |
| Viewer | Read-only | None | None | None |
Beyond those columns, Manager also gets full access to leads, proposals, docs, files, calendar, operations, the wiki, forms, and the service catalog, with view access to automations and the archive. Member gets its own scope on inbox, docs, and files, and view access to calendar, wiki, forms, and the service catalog. Viewer can look at projects, inbox, docs, files, calendar, wiki, forms, and the service catalog without changing anything.
The practical read: Manager is your delivery lead or account manager, Member is your freelancer or specialist on named projects, and Viewer is the person who needs to stay informed without touching the work. More on structuring this in how to manage team roles and access.
Seat licences everywhere, or one workspace
Adding a contractor usually means a paid seat in the project tool, another in the file tool, and another in chat, with different permission models in each. Arpixa gives them one role in one workspace.
Invites, seats, and offboarding
Inviting someone takes an email address, an optional name, and a role, picked from cards that spell out what each role can do. Arpixa checks before sending that the person is not already an active member or already invited, so you do not create duplicates.
On the invitee's side, acceptance is a real check rather than a formality. Arpixa looks at whether that account can join: an address already registered as an agency owner, as a client, or as a team member of a different workspace is stopped with an explanation, so you never end up with a half-joined account that behaves oddly. On acceptance they set the display name their teammates will see.
Seats are counted honestly: active members plus pending invites. Free includes 2, Starter includes 15, Pro and Advanced are unlimited. If a downgrade puts you over the limit, Arpixa hides the extra members instead of deleting them, and shows how many are hidden, so upgrading restores the team rather than rebuilding it.
Offboarding is one action. Remove a member and their workspace access is revoked. Revoke an accepted client invite and they are disconnected on their next session. Nothing lingers because someone forgot to remove a shared password.
How it connects to the rest of Arpixa
- Roles decide whether money columns render on project boards and lists, and whether client Overview, Invoices, and Payments tabs appear in the CRM.
- Project assignments scope what a Member sees, including the time entries and clients attached to those projects.
- Analytics reports team utilisation from tracked time, billable and non-billable.
- The Resource Planner in Ops Hub shows who is loaded and who is free across a rolling window, and lets you assign someone to a project on the spot.
- Client-facing access is a completely separate system: clients get the client portal, never a team seat.
Bring the team in without opening the books
Start free in minutes, or log in to your Arpixa workspace. See pricing for plan details.
Arpixa has a real Free plan (not a trial), with Starter at $12/month, Pro at $29/month, and Advanced at $89/month. Team seats are 2 on Free, 15 on Starter, and unlimited on Pro and Advanced, with pending invites counting toward the limit. Annual billing lowers the effective monthly cost, and the pricing page is the source of truth for current plan limits.
How to set up your team
- Open Team Management and invite a teammate by email, giving them a role at the same time.
- Pick the role by what they need: Manager for client-facing delivery leads, Member for assigned project work, Viewer for read-only visibility.
- For anyone on the Member role, open the assignment panel and assign the projects they should see.
- Ask the invitee to accept from their own account, where they set the display name teammates will see.
- Change a role inline as responsibilities shift; permissions update with it.
- Remove a member or revoke an invite when a contract ends, which cuts workspace access.
For the day-to-day side of this, see how to assign work to your team and how to know what your team is working on.
Frequently asked questions
What roles does Arpixa support?
Five: Owner, Admin, Manager, Member, and Viewer. Owner and Admin have full access across the workspace. Manager manages projects, clients, leads, proposals, docs, files, calendar, and operations but has no access to invoices, financials, analytics, or settings. Member works only on assigned projects with no financial access. Viewer is read-only. Owner cannot be assigned to someone else from the invite screen.
Can I give someone project access without showing them revenue?
Yes, and that is the normal case. Financial visibility is its own permission area, separate from project access. The Manager, Member, and Viewer roles all have financials set to none, which means the Overview, Invoices, and Payments tabs on a client record and the money columns on project lists simply do not render for them.
How does project-level access work?
The Member role has project permission set to "own", which triggers assignment-based scoping: they see only projects explicitly assigned to them, and the clients and time entries attached to those projects. You manage assignments from a panel on the team table with search and bulk select. Until a Member has at least one assignment, the table shows a warning marker because they will see nothing.
Do pending invites count against my seat limit?
Yes. Arpixa counts active members plus pending invites when checking your plan limit, so a seat you have offered is a seat you have used. The Free plan includes 2 team members, Starter includes 15, and Pro and Advanced are unlimited. If you exceed the limit after a downgrade, the extra members are hidden rather than deleted, and reappear when you upgrade.
What happens when someone accepts an invite?
They accept from their own signed-in account and choose the display name teammates will see. Arpixa checks first that the account can accept: an address already used as an agency owner, a client, or a team member of another workspace is blocked with an explanation rather than half-joined. Accepted, they land in the workspace with the permissions their role defines.
Is there an audit trail of what the team does?
Yes. The workspace activity log records events such as creating, updating, archiving, and restoring projects, creating, sending, and deleting invoices, adding and updating clients, inviting and removing members, updating settings, logins, automation runs and failures, proposals created and viewed, contracts signed, and meetings booked. It can be filtered by user, action, and date range and exported.