01
Platform owner
Full reach across every workspace. The only role that can create a new workspace from an approved request.
ScavoSecurity
Scavo is a private workspace, not a public tool. Access is granted per operator, scoped per workspace, and enforced on every request.
Permissions
This table mirrors the permission matrix the product enforces today. Roles are checked server side, so a hidden button is never the only thing standing between someone and an action.
| Permission | Owner | Admin | Manager | Operator | Viewer |
|---|---|---|---|---|---|
| Reply to conversations | Allowed | Allowed | Allowed | Allowed | Not allowed |
| Assign owners | Allowed | Allowed | Allowed | Allowed | Not allowed |
| View analytics | Allowed | Allowed | Allowed | Allowed | Allowed |
| Publish automations | Allowed | Allowed | Allowed | Not allowed | Not allowed |
| Invite members | Allowed | Allowed | Allowed | Not allowed | Not allowed |
| Manage members | Allowed | Allowed | Not allowed | Not allowed | Not allowed |
| Review approvals | Allowed | Allowed | Not allowed | Not allowed | Not allowed |
| Manage integrations | Allowed | Allowed | Not allowed | Not allowed | Not allowed |
| View audit log | Allowed | Allowed | Allowed | Not allowed | Not allowed |
| Create workspaces | Allowed | Not allowed | Not allowed | Not allowed | Not allowed |
Roles
01
Full reach across every workspace. The only role that can create a new workspace from an approved request.
02
Everything inside their own workspace: members, integrations, approvals, automations, and the audit log.
03
Runs the floor. Invites members, publishes automations, replies and assigns, and reads the audit log.
04
Works conversations. Replies, assigns owners, and sees analytics, with no access to settings or approvals.
05
Read-only analytics. Useful for a client or a stakeholder who should see outcomes but never touch a thread.
Guarantees
01
An uninvited signup does not get a workspace. It creates a request that waits for an owner decision, and the account stays pending until then.
02
Tenant and role come from the server session on every protected request. A client cannot ask for another workspace's data by changing a parameter.
03
Workspace decisions, member changes, approvals, and lead tag edits are written to an audit log with the actor and the details.
04
Automatic DM sending without operator review is a high-risk approval that stays pending until you grant it.
05
Passwords are scrypt-hashed with a per-account salt. Sessions are database-backed, HTTP-only, and expire.
06
Five failed sign-ins locks the account for fifteen minutes.
Scavo is a private workspace. Request access and the Scavolution team will approve your account and set the playbook up with you.
Request access