Skip to content

Roles and permissions

  • A role is the label a user carries: system_admin, company_admin, company_staff, or one you create yourself.
  • A permission is an individual capability. Roles are built from permissions.

Assigning someone a role is done from Team and users. These screens are about editing the roles and permissions themselves.

Admin → Roles.

The roles list showing each role's name and when it was created and last updated

Each role is listed with its Name, Created On and Updated On. Create Role adds a new one.

Roles are scoped to your company. You only ever see and edit your own company’s roles, and another company’s administrator can never reach yours.

There is nothing magic about the name system_admin. When you create a role you choose its permissions freely, so you can build a role that holds everything a system administrator holds — or any subset of it. If your company wants a “Head of Content” or a “Finance” role with a precise slice of access, create it and grant exactly the permissions it needs.

What you cannot do is change the default system_admin role.

This is deliberate, and it protects you from a mistake that cannot be undone from inside the product.

Managing roles is itself a permission. If an administrator removed that permission from every role that held it — easily done while tidying up a role’s access — then nobody in the company would be able to edit roles or permissions ever again. The screens that would let you put it back are the very screens you just locked yourself out of. The company would be stuck that way permanently, with no self-service route out.

Freezing the default system_admin guarantees that at least one role always retains the ability to manage roles and permissions. It is the floor you cannot fall through.

Its name and permission set are a design constant, changeable only by an InsightsRN engineering change, never through the UI.

Roles cannot be deleted from the app — there is no delete action, for custom roles or default ones. If a role is no longer needed, move its users onto a different role from Team and users and leave it unused.

Admin → Permissions.

The permissions list showing each permission's name and description

Every permission is listed with a Name and a Description saying what it grants, alongside its created and updated dates. The list is long enough to be paginated.