Skip to main content

Members and permissions

Everyone who signs in to Gradient is a member of one organization. Each member holds one of four roles: owner, admin, member, or reviewer. The role decides what that person can do in the workspace.
A workspace role is not the same thing as a role, which is a job opening you are hiring for. This page is about permissions. Manage members at Settings, Team.

The four workspace roles: Owner, admin, member, and reviewer

Owner

Commercial and existential control: billing, single sign-on, data retention, and who holds the owner and admin seats. The person who creates the organization is the first owner.

Admin

How the workspace is set up: the org profile and branding, API keys, ATS integrations, inviting members and reviewers, and permanent deletion.

Member

The everyday recruiting role. Members build assessments, invite candidates, score, and release feedback. This is the role most of your team should hold.

Reviewer

Read-only. Reviewers open a candidate report and read all of it, including the transcript and the scores, and export what they read. They change nothing.
The hierarchy is owner > admin > member > reviewer. Each role includes everything the role below it can do.
Give people member unless they need to configure the workspace. A member can run a hiring process from end to end and change nothing about the company.

Permissions by role

Reading

Running your hiring

Setting up the workspace

Owner only

Everyone edits their own profile, whatever their role.

Deleting work: Remove, delete permanently, and reopen

Three actions delete work, and they do not carry the same risk.
  • Remove puts a candidate or an assessment in the trash. You can restore it. Members and above can do this.
  • Delete permanently erases the record and all of its files. You cannot restore it. Admins and above only.
  • Reopen a session discards the work in that phase and every phase after it, and replaces a score a reviewer may have read already. Members and above.
Reviewers cannot delete or reopen anything.

Default role settings

There are four ways a person joins your organization, and each one sets the role differently.
Auto-join gives a new person access to every candidate report in the workspace as soon as they sign in with a matching email address. Turn it on only for domains you control, and review the member list after you enable it.

Inviting a member

1

Open Settings, Team

You must be an owner or an admin.
2

Click Invite member

Enter the work email address and choose the role. Only an owner can choose Owner or Admin.
3

Send the invitation

Gradient emails a sign-in link. Clear Send email if you want to create the member record now and tell them yourself later. Use Resend on the member row if the link expires.
An invited person keeps the role from the invitation when they first sign in.

Changing a role or removing a member

Open Settings, Team, then use the role menu on the member’s row, or Remove. Three rules protect the workspace:
  • Only an owner can invite, promote, demote, or remove an owner or an admin. An admin staffs the tiers below it, not its own.
  • Admins can invite, re-role, and remove members and reviewers.
  • The last owner cannot be demoted or removed. Promote a second owner first.
Removing a member ends their access at once. Their name stays on the work they did, such as a score they changed, so your history stays readable.

Role sources: Direct, SAML group, SCIM group, and heuristic

Gradient records the source of every member’s role, because it is the first question an identity team asks. If your organization uses SSO with group mapping or SCIM, your identity provider is the source of truth. Gradient mirrors what it sends and never overrides it:
  • A group change in your identity provider reaches Gradient within about five minutes. A new sign-in is always current.
  • For SCIM-managed organizations, the invite and remove controls on Settings, Team are hidden. Add and remove people in your directory instead.
To map a directory group to a role, use the role names exactly: owner, admin, member, or reviewer.

Candidate access

A candidate never signs in and never holds a role. Their assessment link is its own credential. Candidates cannot see the dashboard, other candidates, or their own score unless you release feedback to them. See Authentication for how candidate links work.