Access control
Who can do what in a workspace that's already running: the roles and permissions you grant, the attributes you record about people, and the policies that decide which teams and channels they can reach.
- Manage team and channel members - Add, remove, and change the roles of members.
- Advanced permissions - Customize what each role is allowed to do.
- Advanced permissions: backend infrastructure - How the permissions system is structured.
- Delegated granular administration - Grant admin access to part of the System Console.
- Attribute-based access control - Grant access based on user attributes rather than membership lists.
- User attributes - Define the custom attributes that access rules are written against.
- System-wide attribute-based access policies - Organization-wide policies System Admins assign to teams and channels.
- Team membership policies - Control who can join a team.
- Team channel policies - Channel membership policies Team Admins manage from Team Settings.
- Channel-specific access rules - Access rules Channel Admins manage from Channel Settings.
Setting up authentication and creating accounts in the first place is covered in onboard users, including guest accounts. For guidance on how to structure teams and channels before you decide who can create them, see workspace organization.