Roles and permissions
Every user belongs to one company and carries exactly one role in it. Three roles are seeded on every company:
| Role | Intended for |
|---|---|
system_admin | The account owner — the company’s highest level of access |
company_admin | Managers — users, company settings and billing |
company_staff | Day-to-day campaign work |
These are the defaults, not the limit. Anyone with the roles-and-permissions permissions can create additional roles with any permission set — see Roles and permissions. The table below describes the seeded three; a custom role can reach whatever its permissions allow.
What each role can reach
Section titled “What each role can reach”| Area | system_admin | company_admin | company_staff |
|---|---|---|---|
| Campaigns, deliverables, clients, publishers | ✅ | ✅ | ✅ |
| Dashboard and reports | ✅ | ✅ | ✅ |
| Personal settings | ✅ | ✅ | ✅ |
| Team and users | ✅ | ✅ | — |
| Company settings | ✅ | ✅ | — |
| Subscription and billing | ✅ | ✅ | — |
| Roles and permissions | ✅ | — | — |
The ticks describe the seeded roles. Access is ultimately decided by the permissions a role carries, not by its name, so a custom role can be given any of the above — see Roles and permissions.
Campaign-level access
Section titled “Campaign-level access”Roles are not the whole story. Access can also be granted per campaign, so staff see only the campaigns they are assigned to.