Your Bron workspace is designed for secure, collaborative asset management. By inviting users and assigning roles, you can distribute responsibilities while maintaining full control over critical actions. Together with security policies and transaction limits, this creates a structured and safe environment for managing assets as a team.
1. User Roles
Bron supports five roles within a workspace:
Owner has full control over the workspace and assets — they can perform any action, including sending, swaps, staking, managing users, and updating security settings. Changes to Owners — adding, removing, upgrading, or downgrading — are protected by the Manage owners policy in Security Policies. Approval always comes from the Owners: the approver pool is every current and future Owner, and individual approvers cannot be picked. When a workspace has multiple Owners, only Owners can configure that policy. When assigning roles, the Owner option is shown only to users who are allowed to assign it.
Member has the same operational access to assets as an Owner and can interact with assets (send, swap, stake), but cannot manage other users or change security settings. Security policies can only be viewed and edited by Owners.
Viewer has read-only access. They can view balances and activity, generate reports, and optionally be set as transaction approvers, but cannot initiate or execute transactions independently.
Guardian is a trusted contact for account recovery — they help regain access to the workspace if it is lost.
Beneficiary is a designated recipient of the workspace assets in the event of the owner's passing or incapacitation. Beneficiaries are configured as part of the inheritance setup — see Inheritance for details.
2. Additional Permissions
Owners can configure additional controls that affect how users interact with the workspace.
Depending on your Security Policies and Transaction Limits settings, users may be required to approve transactions before execution, approve transaction limit changes, approve address book updates, or approve user changes.
These approval requirements depend on your workspace configuration: if User approval is enabled on a policy, the users listed as Authorized approvers must approve the action; if Security delay is chosen instead, the action is held for 48 hours and then applies on its own. Transaction limits can also require approvals or delays depending on the configured rules.
Approver rights are granted per policy, not per role. Selecting a user as an authorised approver for policy changes, transaction limits, the address book or user changes gives them approval rights for that area only — it does not change their role, and a Viewer can be an approver. Every approval rule needs at least 2 approvals, and the person who requested the change counts as the first approver, so a second person always has to act. Nobody can approve their own request.
For more details about how approvals and protections work, see Security Policies.
3. Adding A New User
To invite a new user to your workspace, enter their email address and assign their role and permissions.
When inviting a Member or Viewer, choose their Account access: either All existing and new accounts (the default — accounts you create later are shared automatically) or a specific set of accounts.
To grant access to a hidden account, you must first unlock it: enter its PIN in the accounts panel to make it visible. The unlocked account will then appear in the account selection list during the invite flow, and you can include it in the user's access.
After the user has been added, you can edit their account access at any time by selecting them in Settings → Users. Note that hidden accounts will only appear in the access list again if you re-enter their PIN in the accounts panel first.
⚠️ If the Manage users policy is enabled in your Security Policies, adding a new user will only take effect after an authorised approver reviews and approves the action — or after the 48-hour security delay, if that is the method you chose.
Once approved, an email invitation is sent to the specified address with a link to set up their account. The invited user must follow the link, set up their passkey, and accept the invitation to join the workspace. After that, they'll be able to take any actions allowed by their role.
When you invite a new Owner, Bron recommends enabling the Manage owners policy as part of the invite, so future Owner changes require approval from the Owners. Enabling a policy for the first time takes effect without a delay or approval; the policy applies from the moment the invite is accepted.
On mobile: go to Profile → Users and tap + to invite a user — choose the user type (Team member, Guardian, or Beneficiary) and assign the role.
4. Editing And Deactivating Users
You can modify the role and permissions of any user, or deactivate them, at any time.
If the Manage users policy is enabled in your Security Policies, these actions will not take effect immediately — they'll either require approval from an authorised approver (User approval) or be applied after a 48-hour Security delay. Both protection methods are available on all plans. This ensures that changes to user access cannot be made instantly without oversight.
4.1. Deactivating A User
When a user is deactivated, they lose all access to the workspace. They will no longer be able to log in, view balances or transaction history, initiate or approve any actions, or interact with the workspace in any way. For a user with no approval duties, this happens immediately.
If the user is an approver for protected settings, deactivation is handled with extra care:
The affected approval rules update automatically to keep the same level of protection: if other approvers remain, the required approval count is adjusted; if this user is the only approver, the policy switches to a 48-hour security delay instead.
The confirmation screen lists the security policies and transaction limits that will be affected.
Such a deactivation applies after a deactivation delay: the user is notified immediately and keeps full access until the security delay ends.
4.2. Leaving The Workspace
If your role is Guardian or Member, you can remove yourself from the workspace at any time. To do this, go to Settings → Workspace Details and click Leave Workspace.
5. Updating A User's Role
To change a user's role:
Go to Settings → Users
Select the user you want to modify
Click Edit and update their role (Owner, Member, Viewer) or downgrade to Guardian if needed
On mobile: Profile → Users → select the user → Edit roles.
Keep in mind that role changes only affect access level. Approval rules are managed separately in Security Policies, and transaction rules are configured in Transaction Limits.
If you have questions, contact our support team via messenger on the Bron platform or by email support@bron.org.
📅 Questions about how this works for your team? Book a call with our product team










