Skip to content
WorksBuddy

Think bigger · Run lighter.

WorksBuddy Logo
WorksBuddy Docs

Roles and Audit Logs

Seven roles with individually gated sensitive actions in Evox, plus an append-only audit log of every action, searchable and exportable.

Outbound touches personal data at volume, so controlling who can reach it and proving what happened is the baseline for any serious team. Roles set the access, and the audit log keeps the record.

How it works

You assign each team member one of seven roles, from owner down to viewer, and each maps to a specific set of capabilities. Sensitive actions are then gated individually rather than bundled: launching a campaign, connecting a mailbox, exporting contacts, approving copy, and changing billing are each permissioned separately, so someone can edit copy without being able to send it. Every create, edit, launch, pause, approval, and delete is written to a log with the person and the exact time, and access logs separately record session, device, and IP history per user. The log is append-only, so entries can never be modified or removed by anyone, including owners and admins.

Key capabilities

  • Seven roles: owner, admin, manager, editor, reviewer, viewer, and billing.
  • Sensitive actions gated one by one instead of bundled into a single admin level.
  • Full action log with actor and timestamp for every change.
  • Separate access log covering session, device, and IP history per user.
  • Append-only storage, uneditable by every role including workspace owners.
  • Searchable in product and fully exportable for auditors, with retention set by plan.

Tips

Keep the export contacts permission narrow. It is the one capability that lets a single account remove your entire contact database, and most roles never need it.