docEvault keeps roles deliberately simple. There are two.
Member
The everyday role. Members do the actual work: create and send requests, manage contacts, review and approve documents, use templates and message sequences.
Admin
Everything a member can do, plus the account-level controls — managing the team, changing roles, and billing.
Changing someone's role
Assign roles from Team. You can promote a member to admin or demote an admin to member at any time.
The sole-admin safeguard
You can't demote the last remaining admin. If an organization could end up with zero admins, nobody could manage the team or billing ever again, so docEvault refuses the change rather than letting you lock yourself out.
If you're the only admin, promote someone else before changing your own role.
What roles don't control
Roles govern the application, not the encryption. Being an admin doesn't automatically let you read documents — that still depends on having the encryption passphrase or being granted access by someone who does. The two systems are separate on purpose.