Guide

Team roles in a Telegram workspace: five, not two

Owner, admin, editor, analyst, support — seventeen permissions. Two can never be delegated, and any member can be adjusted above or below their role.

AdminHub

TL;DR. Five roles, not the usual two: owner, admin, editor, analyst, support. Between them they cover seventeen permissions. Two of those — deleting the workspace and transferring it — belong to the owner and cannot be delegated to anyone under any circumstances. Everything else can be adjusted per person: add a permission on top of a role, or take one away, without inventing a new role.

Most tools give you an owner and an admin, which means every decision about access is really the same question: do I trust this person with everything or with nothing. That question has a wrong answer for almost every real teammate.

What the five roles actually are

Owner has everything, including the two things nobody else can have.

Admin has everything except deleting the workspace and transferring it. In practice this is a co-owner who cannot end the business.

Editor publishes, schedules, runs content sources and the AI writer, moderates comments and manages people — but has no access to money. The role for someone who runs your channel.

Analyst reads people and views analytics. Nothing else, and nothing they can change. The role for a contractor you want to show numbers to.

Support reads and manages people, moderates, handles operations and support — and can issue a refund. But cannot publish. The role for someone answering customers.

Support is where two roles break first

A person answering your customers needs to be able to refund someone on the spot; they have no business posting to your channel. In a two-role tool you must choose which of those two mistakes to make.

That is the whole argument for five roles. And it arrives early — the first day someone other than the owner answers a customer.

Adjusting one person without inventing a role

Each member carries their role plus an individual adjustment: permissions granted on top, permissions taken away. An editor who also needs analytics gets that one permission rather than a promotion. An admin who should stay away from monetisation loses that one rather than a demotion.

Use this sparingly. A team where everyone has a bespoke permission set is a team where nobody can say what anyone can do — the roles exist so that most people need no adjustment at all.

The two you can never give away

Deleting the workspace and transferring it are owner-only, and not by convention. Individual grants are filtered against the real permission list first, and the two owner-only ones are subtracted afterwards, so they cannot be handed over by mistake, by a typo, or by pasting a wildcard into the field.

Neither action can be undone by whoever it lands on. That is exactly why neither can be handed over.

If… then…

If…Then…
Someone runs your channelEditor — publishes, no money
Someone answers customersSupport — refunds, no publishing
A contractor needs to see numbersAnalyst — reads and nothing else
You need a second youAdmin — everything but ending the business
One person needs one extra thingAdjust that person, don’t promote them
You want to hand over the workspaceOnly the owner can, and only deliberately

Where to start

Look at whoever currently has admin because there was nothing else to give them. In most small teams that is one person doing one job — usually answering customers — who was handed the keys to everything because the tool offered two options.

Move them to the role that matches the job, then add back the single permission they turn out to need. That is usually the whole migration, and it takes about a minute.


The workspace this applies to — the shop page. Who your subscribers are — orders in a Telegram shop. What an editor actually publishes — the post editor.

What people usually ask

What are the five roles?
Owner, admin, editor, analyst and support. The owner has everything. An admin has everything except deleting or transferring the workspace. An editor publishes and moderates but cannot touch money. An analyst reads people and analytics and changes nothing. Support handles customers — including refunds — but cannot publish.
Can I give someone one extra permission without promoting them?
Yes. Each member carries their role plus an individual adjustment: permissions added on top and permissions taken away. So an editor who also needs to see analytics does not have to become an admin.
Is there anything I can never hand over?
Two things: deleting the workspace and transferring it. They are owner-only and the code strips them out of any individual grant, so they cannot be given away even by mistake.
Why can support issue refunds but not publish?
Because those are different jobs. Someone answering customers needs to make a refund right then; they have no reason to be able to post to your channel. Two roles in most tools would force you to choose between giving them too much or too little.
Can I take a permission away from someone's role?
Yes — the adjustment works in both directions. An admin who should not touch monetisation can have that removed while keeping the rest.
What happens if someone tries to grant themselves everything?
Nothing. Individual grants are filtered against the real permission list, so an arbitrary string or a wildcard does not escalate anything — it is simply dropped.