Access and permissions

Hoko uses two permission levels: workspace authority and collection access. Your effective access is the combination of both levels.

How access works

Your signed-in profile must belong to the active workspace. The workspace role controls workspace-wide features. Your collection role controls data inside each collection.

Workspace owners and Workspace Admins receive access to every active collection. Ordinary members see only collections where they have an assigned role.

Protected resources and changes are checked on the server. Hiding a button alone does not set a permission, and a direct URL cannot bypass a protected action.

Access matrix

The matrix shows effective access for each role. All means every active collection; Assigned means collections with that role; Workspace means the whole workspace; Self means your own account. Read means view only, Manage means the action is allowed, and No means it is blocked. Business+ and Plan permitting also require the stated plan allowance.

On a narrow screen, scroll each table sideways to see every role.

Workspace and membership

Feature Owner Workspace Admin Collection Admin Editor Viewer No access
View workspace in switcher Workspace Workspace Workspace Workspace Workspace Workspace
View workspace settings Read Read No No No No
Update workspace name Manage Manage No No No No
Update workspace slug Manage Manage No No No No
Update workspace image Manage Manage No No No No
View Participants Workspace Workspace Assigned admin collections No No No
Invite across any collection Manage Manage No No No No
View pending invitations Workspace Workspace Assigned admin collections No No No
Resend an invitation Manage Manage Assigned admin collections No No No
Revoke an invitation Manage Manage Assigned admin collections No No No
Invite a Collection Admin Manage Manage No No No No
Invite an Editor to an assigned collection Manage Manage Manage No No No
Invite a Viewer to an assigned collection Manage Manage Manage No No No
Promote Viewer to Editor Manage Manage Manage No No No
Promote Editor to Collection Admin Manage Manage No No No No
Demote Collection Admin to Editor Manage Manage No No No No
Demote Editor to Viewer Manage Manage Manage No No No
Remove a workspace member Manage Manage ordinary members No No No No
Remove a member from an assigned collection Manage Manage Manage No No No
Grant Workspace Admin Manage No No No No No
Revoke Workspace Admin Manage No No No No No
Transfer ownership Manage No No No No No
Leave the workspace Transfer first Yes Yes Yes Yes Yes
Feature Owner Workspace Admin Collection Admin Editor Viewer No access
List collections All All Assigned Assigned Assigned No
View collection details All All Assigned Assigned Assigned No
Create a collection Manage Manage No No No No
Rename a collection Manage Manage Assigned No No No
Set the default collection Manage Manage No No No No
Delete a collection Manage Manage No No No No
View links All All Assigned Assigned Assigned No
Create a link All All Assigned Assigned No No
Edit link metadata All All Assigned Assigned No No
Change link destination All All Assigned Assigned No No
Change link preview All All Assigned Assigned No No
Change link targeting All All Assigned Assigned No No
Change link expiration All All Assigned Assigned No No
Change link password protection All All Assigned Assigned No No
Change link QR settings All All Assigned Assigned No No
Move a link All All Assigned source and destination Assigned source and destination No No
Delete a link All All Assigned Assigned No No
View link analytics All All Assigned Assigned Assigned No

Shared libraries and reports

Feature Owner Workspace Admin Collection Admin Editor Viewer No access
View tags library Read Read No No No No
See shared option names on Links page All All Assigned Assigned Assigned No
Create a tag Manage Manage No No No No
Update a tag Manage Manage No No No No
Delete a tag Manage Manage No No No No
Use existing tags on assigned links All All Assigned Assigned No No
View UTM templates library Read Read No No No No
Create a UTM template Manage Manage No No No No
Update a UTM template Manage Manage No No No No
Delete a UTM template Manage Manage No No No No
View partners library Read Read No No No No
Create a partner Manage Manage No No No No
Update a partner Manage Manage No No No No
Delete a partner Manage Manage No No No No
View customers All All Assigned Assigned Assigned No
View click analytics All All Assigned Assigned Assigned No
View lead analytics All All Assigned Assigned Assigned No
View sale analytics All All Assigned Assigned Assigned No
View Events All All Assigned Assigned Assigned No
View Journeys All All Assigned Assigned Assigned No

Integrations and billing

Feature Owner Workspace Admin Collection Admin Editor Viewer No access
View API key metadata Read Read No No No No
Create an API key Manage Manage No No No No
Rename an API key Manage Manage No No No No
Change API key scopes Manage Manage No No No No
Change API key allowed hostnames Manage Manage No No No No
Revoke an API key Manage Manage No No No No
View webhook endpoints Read Read No No No No
Create a webhook endpoint Business+ Business+ No No No No
Update a webhook destination Manage Manage No No No No
Verify a webhook Business+ Business+ No No No No
Enable a verified webhook Business+ Business+ No No No No
Disable a webhook Manage Manage No No No No
Delete a webhook Manage Manage No No No No
Send a webhook test Business+ Business+ No No No No
View webhook delivery history Read Read No No No No
View delivery attempt details Read Read No No No No
View webhook test attempts Read Read No No No No
View activity logs Read Read No No No No
Export visible logs Plan permitting Plan permitting No No No No
Resend an eligible delivery Business+ Business+ No No No No
View billing Read No No No No No
Change the subscription Manage No No No No No
Open the billing portal Manage No No No No No
View invoice details Read No No No No No
Send invoice email Manage No No No No No
View subscription usage Workspace Workspace Workspace Workspace Workspace Workspace

Personal account

Feature Owner Workspace Admin Collection Admin Editor Viewer No access
View own profile Self Self Self Self Self Self
Update own profile Self Self Self Self Self Self
Change own language Self Self Self Self Self Self
Change own appearance Self Self Self Self Self Self

The No access column describes collection access. An ordinary workspace member with no collection assignment can still see the workspace switcher and subscription usage, but Collections, Links, and Analytics show an explicit no-access state. Owners and Workspace Admins keep the normal empty or onboarding state when the workspace has no collections because they have workspace-wide collection access. Some protected pages return an access-restricted state when the member lacks workspace authority.

Workspace roles

Owner

The Owner has full workspace access. The Owner can:

  • update workspace settings;
  • create, rename, set as default, and delete collections;
  • invite and remove workspace members;
  • assign collection roles;
  • create and manage API keys;
  • create and manage webhooks;
  • view logs and resend eligible webhook deliveries;
  • manage billing and subscription changes;
  • appoint or remove Workspace Admins; and
  • transfer workspace ownership.

The Owner role cannot be removed through an ordinary member update. Use the dedicated ownership transfer action.

Workspace Admin

Workspace Admin is a workspace-wide operational role. A Workspace Admin can:

  • update workspace settings;
  • create, rename, set as default, and delete collections;
  • invite and remove ordinary workspace members;
  • assign collection roles below Workspace Admin authority;
  • create and manage API keys;
  • create and manage webhooks;
  • view logs and resend eligible webhook deliveries; and
  • work with all active collections.

A Workspace Admin cannot manage billing, transfer ownership, appoint or remove another Workspace Admin, or change the Owner.

Member

Member is the base workspace role. A Member has no workspace-wide management rights. Their access comes from the collection roles assigned to them.

Collection roles

Collection roles can differ for each collection.

Collection Admin

Collection Admin can rename collections where they are Collection Admin. They can manage members for those collections and invite or update Editors and Viewers within that scope. They cannot create or delete collections, manage workspace settings, manage API keys or webhooks, view workspace logs, manage billing, or appoint Workspace Admins.

Editor

Editor can create, edit, move, and delete links in assigned collections. Editor can use shared tags, partners, and UTM options while editing assigned links. Editor cannot manage members, collections, API keys, webhooks, logs, or billing.

Viewer

Viewer can read assigned collection data, links, analytics, customers, and available reports. Viewer cannot create, edit, delete, or manage access.

No access

No access means that no collection role is assigned. The member can remain in the workspace but cannot read collection data or use collection features.

Feature boundaries

Workspace settings

Only the Owner and Workspace Admin can open and update workspace settings. Only the Owner can transfer ownership or manage Workspace Admin roles.

Collections

The Owner and Workspace Admin can create, set the default, and delete collections. The Owner and Workspace Admin can rename any collection. Collection Admin can rename an assigned collection. Editor and Viewer cannot perform collection management operations.

Members

The Owner and Workspace Admin can manage workspace membership. Collection Admin can manage collection assignments within collections where they are an administrator. A Collection Admin cannot remove a person from the entire workspace.

Shared libraries

The Owner and Workspace Admin can manage tags, partners, and UTM templates. These libraries are workspace-wide. The Links page can show their option names to anyone with collection access, including Viewers, even when they cannot open the library management pages. Collection Admins and Editors can apply those options to links they can edit.

Collection Admin and Editor can manage links in assigned collections. Viewer has read-only access. Owner and Workspace Admin have access across active collections.

Analytics and customer views follow the same collection scope. A plan may limit a report, export, or analytics feature after the role check succeeds.

API keys

Only the Owner and Workspace Admin can view, create, update, and revoke workspace API keys. API key scopes control what an integration can do through the API. A key does not grant access to the dashboard, webhooks, logs, or billing.

API keys belong to the workspace. Changing the creator's human role does not revoke a key. Revoke the key explicitly when its integration must stop.

Treat every key as a password. Copy its secret when it is created, store it on the server, and revoke it when it is no longer needed.

Webhooks and logs

Only the Owner and Workspace Admin can manage workspace webhooks or open workspace logs. Webhooks require an eligible plan. Current product policy requires Business or above for webhook creation, verification, testing, and delivery.

An Owner or Workspace Admin on an eligible plan can resend a pending, failed, or Unconfirmed delivery from the log row's More options menu when the endpoint is active. Hoko waits five minutes before allowing an Unconfirmed delivery to be resent. A pending delivery uses its existing first attempt. A failed delivery or an old Unconfirmed delivery adds a new attempt. Every resend keeps the original event ID.

Delivery history remains available after an endpoint is disabled or deleted. A deleted endpoint cannot deliver or be resent.

Billing

Only the Owner can view billing controls, start checkout, change the subscription, open the billing portal, or manage invoices. A Workspace Admin can view operational workspace data but cannot change billing.

Plan limits

Role and plan checks both apply to protected features. A member with the required role can still see a plan restriction when the workspace plan does not include a feature.

Plan restrictions do not grant access to a different role. Upgrading a plan does not grant access to workspace settings, integrations, logs, or billing.

No-access states

If you are an ordinary workspace member with no collection assignment, Hoko shows an explicit no-access state in Collections, Links, and Analytics and explains that a collection role is required. Owners and Workspace Admins see the normal empty or onboarding state when their workspace has no collections. If you are not a member of the workspace, Hoko does not reveal the workspace and returns a not-found response for protected resources.

After a membership is removed or blocked, subsequent protected requests fail. Refresh the page and select another collection that you can access.

Change access

Open Dashboard → Settings → Participants.

The Owner can update workspace roles. The Owner and Workspace Admin can update ordinary member collection roles. Collection Admin can update roles only within collections where they have Collection Admin access.

Use the dedicated Transfer ownership action to move ownership. Do not try to transfer ownership by changing a collection role.

  • Participants explains invitations and collection assignments.
  • Collections explains collection lifecycle.
  • API keys explains scopes and key handling.
  • Webhooks explains endpoint setup and delivery behavior.
  • Logs explains activity history and delivery attempts.
  • Billing explains subscription controls.