Everyone in an organization is an owner or a member. The person who registers the org becomes its first owner; everyone else joins by invitation with a role chosen by whoever invited them.

What only an owner can do

Action
Rename the organization
Invite a member
See the pending invites
Revoke an invite
Change a member’s role
Remove a member
A member attempting one of these gets a “not org owner” error from the server; the app hides the controls.

What everyone can do

Everything else in the product is scoped to the organization rather than to a role. A member can read and write customers, companies, segments, deals, tasks and campaigns; activate and pause campaigns; read the whole inbox and reply in it; connect credentials and AI providers; and upload knowledge-base documents.
Connecting credentials is not restricted by role, and a credential holds a mailbox password or an AWS key. Treat membership of an org as a trusted position, and keep the member list under Workspace Settings short.

The last owner

An organization must always keep at least one owner. Demoting or removing the last one is refused, so hand ownership over before you leave.

Ownership of records

Owning a record is separate from your role. A customer or deal has a claimedById naming the sales rep responsible for it — see Customers. Claiming decides who is expected to act, not who is allowed to.