- Keeping the workspace available if a key employee is absent or leaves
- Managing users and shared workspace standards
- Building and maintaining individual automations
- Controlling the external app accounts connected to those automations
Those jobs carry different risks. Someone who can update a lead-routing Zap does not automatically need billing access, user-management rights, or permission to use a company-wide finance connection.
For most teams, assign two workspace owners, two to three administrators per 25 active users, builders only for named automation owners, and two custodians for every shared app connection. Keep billing, user management, security settings, and connection sharing out of the hands of casual users.
Set Up a Four-Layer Access Policy
Assign responsibilities before inviting a large group into the workspace. Giving broad builder access to everyone may speed up early setup, but it leaves behind duplicate workflows, unclear ownership, and app connections tied to people who no longer maintain the work.
Use this structure as a starting policy:
| Access layer | Who should have it | Recommended number | What they handle | Keep out of their hands |
|---|---|---|---|---|
| Workspace owner | Senior operations, IT, or systems leaders responsible for continuity | 2 people | Account continuity, billing, top-level settings, and recovery decisions | Routine workflow edits unless they also own a workflow |
| Administrator | People responsible for access management and workspace standards | 2 to 3 per 25 active users | User access, workspace organization, and approved operational changes | Broad app credentials without a business reason |
| Builder | Named owners of active or planned automations | Only as needed | Creating, repairing, and retiring assigned Zaps | Billing, user management, and security controls |
| Connection custodian | People accountable for a shared external app account | 2 people per shared connection | Reauthorization, credential changes, and app-side access requests | Workspace-wide administration unless separately assigned |
People who only need a workflow changed do not need Zapier access. Sales reps, department managers, and stakeholders can submit a request to the workflow owner instead of receiving builder rights for a one-time edit.
Every live workflow should have:
- A primary owner
- A backup owner
- A short business purpose
- A list of connected apps
- A last-review date
- An approver for changes when the workflow affects customers, records, or sensitive systems
An automation without an accountable owner becomes difficult to repair during an outage, transfer during offboarding, or retire when the process changes.
Keep Workspace Roles Separate From App Access
Zapier workspace permissions and app authorizations are not the same control.
Workspace access governs what a person can do in Zapier. The connected app account governs what the automation can read, create, update, delete, or send in the external system.
That distinction matters most when a workflow touches a CRM, shared inbox, finance platform, help desk, database, or employee system. A builder with limited workspace access can still create a serious exposure if the app connection has company-wide permissions.
Use the closest available role in your Zapier plan to support these assignments:
- Workspace owners keep the account recoverable. Assign a primary owner and a recovery owner, ideally from separate teams such as Operations and IT.
- Administrators manage access and workspace standards. They should not become default owners of every department’s workflows.
- Builders maintain automations in a defined business area. Give this access to people who are responsible for updating fields, fixing failed steps, and retiring obsolete Zaps.
- Connection custodians manage the external account behind a shared connection. They coordinate reauthorization, approve app permission scopes, and work with the business-system owner when access changes.
For example, a builder creating a single invoice notification should not receive a finance connection with access to every company record. Use an account with only the access that workflow needs.
Choose the Right Connection for the Workflow
A connection can be personal, shared, or tied to a dedicated service account. The right choice depends on whether the workflow belongs to one person or needs to survive staff changes.
| Connection type | Use it for | Avoid it for | Ownership rule |
|---|---|---|---|
| Personal connection | Individual productivity workflows using only that person's own data | Shared processes, customer communications, and workflows another employee must maintain | The individual user is responsible for the workflow and connection |
| Shared managed connection | Team workflows that update shared records, route tickets, or send customer communications | Unmanaged accounts or credentials passed between employees | Assign a primary and backup custodian |
| Dedicated service account | Production workflows involving sensitive systems, high-value records, or business-critical processes | Low-risk personal experiments | Use named custodians and a business-system owner |
Personal connections are quick to set up, but they create an employee dependency. A workflow may stop working after a password reset, account change, employee departure, or revoked authorization.
Shared connections solve that continuity problem, but they need tighter management. One shared connection may support several workflows, so a broad authorization or careless workflow edit can affect multiple teams.
Do not share human login credentials to create a shared connection. Use an approved shared mailbox, managed service account, or app-supported team account. Access revocation and responsibility should stay tied to named people, not a password circulating within a department.
Assign Access by Workflow Risk
Give access based on what the workflow does, not the seniority of the person requesting it.
A department head may approve a lead-routing rule without needing builder access. Meanwhile, a marketing operations specialist may need builder access because they are responsible for maintaining that rule.
| Team and workflow | Who gets builder access | Connection approach | Who approves changes |
|---|---|---|---|
| Marketing: form lead routing | Marketing operations owner and backup | Shared form, email, and CRM accounts | Sales operations approves routing logic |
| Sales: CRM follow-up tasks | Sales operations or revenue systems owner | Managed CRM connection with limited scope | CRM owner approves field and ownership changes |
| Support: ticket escalation alerts | Support operations owner and backup | Shared help desk and messaging connections | Support leader approves customer-facing changes |
| Operations: employee or financial records | Restricted operations administrator | Dedicated service account with least privilege | Security and system owner approve changes |
Treat a workflow as higher risk when an error could:
- Change a customer record
- Send an external message
- Move money or alter financial information
- Expose employee information
- Change permissions in another system
- Trigger a downstream process that is difficult to reverse
These workflows need a named owner, a backup owner, and approval before edits go live.
Keep experiments separate from production automations. Use a clearly labeled test area, test connections, and non-customer records when changing customer-facing logic or workflows that write to operational systems. Editing a live Zap just to see what happens can create duplicate records, unwanted messages, or incorrect updates.
Review Access After 30 Days, Then Every 90 Days
New access should receive a review after 30 days. That catches people invited for a launch project who no longer own a workflow or need workspace access.
Review the full workspace every 90 days. Look for:
- Builders who no longer maintain automations
- Workflows with no owner or backup owner
- Duplicate workflows covering the same process
- Personal connections supporting team processes
- Connections tied to changing job responsibilities
- Automations that have expanded from internal alerts into customer-facing or record-writing work
Run an immediate access review when:
- An employee leaves or changes departments
- A shared app account is reauthorized
- An app connection receives broader permissions
- A critical workflow moves to a new owner
- A new system becomes a source of customer, employee, financial, or regulated data
- A workflow begins sending external messages or writing records
A simple naming system makes these reviews much easier. Name workflows by department, process, and environment, such as Sales | Lead Routing | Production.
Record the owner in the workflow description or linked team documentation. Do not rely on tribal knowledge or a former employee’s inbox.
Maintain a separate inventory for shared connections. Include:
- App name
- Primary custodian
- Backup custodian
- Related workflows
- Business-system owner
- Date of the last authorization review
That inventory speeds up offboarding and app-account changes because the team can identify affected workflows without searching through individual Zaps.
Build the Policy Around Available Controls
Your access policy needs to match the roles and controls available in your Zapier plan, as well as the permissions granted inside each connected app.
Before rolling out broad access, establish how your workspace handles these four areas:
- Workspace roles: Identify which roles can invite users, manage shared assets, and change account-level settings.
- Shared connection governance: Define who can create, use, reauthorize, and maintain shared connections.
- Identity management: Set rules for single sign-on, domain restrictions, and automated provisioning where your organization uses them.
- App-side permissions: Review what each connection can read, create, update, delete, or send.
Single sign-on helps control who can sign in. It does not limit the CRM records, inboxes, files, channels, or finance data already available through a connected app account.
Avoid using production administrator accounts for every connection. A dedicated account with limited access reduces the impact of a faulty field mapping or an incorrectly triggered automation.
When Broad Builder Access Is the Wrong Approach
Do not give wide self-service builder access to teams handling highly sensitive data or systems with weak audit controls.
A more controlled setup is appropriate when automations:
- Change payroll, payment, tax, or banking records
- Send regulated or confidential information to third parties
- Create legally binding customer communications
- Modify permissions in another business system
- Synchronize large volumes of records without a rollback plan
For these processes, use a central automation owner, a restricted production workspace, dedicated service credentials, and formal change approval.
Zapier should not be the only audit record for a high-risk business process. Keep the system owner, approval record, and reason for the change in the team’s established documentation or ticketing process.
This access model also cannot solve unmanaged external accounts. A shared password, former employee’s email address, or unknown CRM administrator remains a risk even if Zapier workspace permissions are tightly controlled.
Setup Checklist
Set the policy before the next wave of invitations.
- Assign one primary workspace owner and one recovery owner.
- Limit administrators to people who manage access or workspace standards.
- Give builder access only to named owners of live or planned workflows.
- Assign a primary and backup custodian to every shared connection.
- Use managed accounts or service accounts for durable production workflows.
- Restrict app permissions to the records and actions each automation needs.
- Label production and test workflows clearly.
- Record the workflow owner, purpose, connected apps, and approver.
- Review new access after 30 days.
- Review the full workspace every 90 days.
- Remove or change access immediately when job duties change.
If the team cannot assign ownership for a workflow or connection, do not expand access around it. Missing ownership usually surfaces later during an outage, employee departure, or security review.
Common Mistakes
Making every department head an administrator
Leadership approval and workspace administration are different responsibilities. Keep department leaders in the approval loop without giving them the ability to invite users, alter connections, or change workspace controls.
Using personal connections for shared processes
A personal email, CRM, or messaging connection turns a business workflow into an employee dependency. Move durable team workflows to managed accounts before a staff change creates an urgent repair.
Treating a Zapier role as the whole security boundary
The connected app account determines the records and actions available to the automation. Restrict app access first, then assign Zapier access.
Giving builders access without an ownership standard
Builder access without a named owner leads to abandoned automations and duplicate workflows. Every live workflow needs someone responsible for keeping it accurate.
Editing production workflows without a test boundary
A live workflow can send customer messages, create duplicate records, or update the wrong information. Use isolated test work before changing customer-facing logic or record-writing automations.
Bottom Line
Set up Zapier permissions around accountability rather than convenience.
Keep two workspace owners for continuity. Limit administrators to people who manage access and workspace standards. Give builder access only to people who maintain named workflows. Put every shared connection under two custodians.
The strongest everyday model is narrow workspace access paired with carefully scoped app credentials. As automations become more business-critical, move from personal connections to managed service accounts, formal approvals, and scheduled access reviews.
FAQ
Who should be a Zapier workspace owner?
Two people should hold workspace owner responsibility: a primary operational owner and a recovery owner who can take over during absence, turnover, or an account issue. Keep this group small because owner-level access carries the greatest continuity and account-control responsibility.
How many Zapier administrators does a team need?
Two to three administrators per 25 active users is a workable ceiling for most teams. Add administrators only when they have a defined access-management or workspace-governance responsibility, not because they need to request workflow changes.
Should every Zapier builder have access to shared app connections?
No. Builders need only the connections required for the workflows they own. Restricting connection access limits accidental use of sensitive data sources and reduces the number of people affected when an external app authorization changes.
What happens if an employee-owned app connection supports a live Zap?
The workflow becomes dependent on that employee’s external account authorization. Transfer the workflow to a managed shared connection or dedicated service account before removing the employee’s access, then test the workflow with the replacement connection.
How often should a team review Zapier permissions?
Review new access after 30 days and review the full workspace every 90 days. Run an immediate review after offboarding, department transfers, app reauthorization, or changes to a workflow that handles customer, financial, employee, or regulated data.