User Guide

Permissions & overrides

A role gets somebody 90% of the way. Overrides handle the last 10% — the one client who is allowed to edit, the one member who needs API access.

Agency

Per-member capability overrides and the permissions matrix are available on the Agency plan. See plans & what's included.

How overrides work

Every member's role sets a default for each capability. An override replaces the default for that one person, and only that person. The role stays what it is — a client with an editing override is still a client everywhere else.

The two halves are sold separately, because they solve different problems:

WhatPlan
Assign a role, including the restricted seatsBusiness and Agency
Override individual capabilities on top of a roleAgency

Change one person's permissions

  1. Settings → Team Members
    Find the person and open their row.
  2. Tick or untick capabilities
    They're grouped: Content, Review, Visibility, Channels & engagement, Workspace, Developer access. Anything you don't touch keeps following the role default.
  3. Save
    It applies straight away, on their next page load.
The common one: a client who wants to fix a typo themselves rather than send the post back. Grant them Create & edit posts and an “Edit post” link appears on the posts they review.

If you run several clients, permissions are set per workspace, so an override you make for one client doesn't follow that person into another.

The full capability list

GroupCapabilities
ContentCreate & edit posts · Schedule & publish posts · Delete posts · Use AI generation (Compose) · See all members' posts
ReviewApprove / reject posts · Required approver (blocks publishing)
VisibilitySee upcoming scheduled calendar · View analytics / reports · View LinkedIn analytics dashboard
Channels & engagementConnect & disconnect channels · Use the social inbox (Engage)
WorkspaceManage voice profiles · Manage tags & topic categories
Developer accessCreate API tokens & MCP access

This is a fixed list, not open-ended rules. Each entry maps to something the app actually checks before it lets an action through, which is why it stays short.

Capabilities that come as a pair

Two combinations don't mean anything on their own, so DemandBird links them for you:

  • Schedule & publish posts needs Create & edit posts. You can't publish what you can't open.
  • Required approver needs Approve / reject posts. You can't be the one blocking publishing without the power to approve.

Ticking the dependent one ticks its prerequisite; unticking a prerequisite unticks the dependent. The same rule is enforced on saves made through the API, not just in the form.

The permissions matrix

Settings → Team Members → Permissions matrix is a read-only grid: one row per capability, one column per person, a tick where they have it. It answers “who can publish?” without opening five member pages.

A ringed cell means that value is an override you set by hand, different from what the role would give. Those are the ones worth auditing before an engagement ends.

The permissions matrix: capabilities down the side, one column per team member, with one ringed cell marking an override.
The matrix columns are account-level roles. If you use multiple workspaces, a person's role can differ per client — open their member page for the per-workspace breakdown.

What can never be overridden

  • Billing and the plan. Admin only, no toggle.
  • Inviting, editing and removing members. Admin only, no toggle.
  • AI prompt templates. Those are shared across every DemandBird account, so they aren't an account-level permission at all.

If your plan changes

Overrides are enforced when they're set, not when they're read. Moving off the Agency plan removes your ability to change them; it does not silently widen a restricted seat back out to its role default. Existing overrides keep applying exactly as they were.