Roles and permissions
Everyone in an organisation has exactly one role. The role decides what they can do — and for most roles, you can adjust that.
The five roles
Section titled “The five roles”| Role | In short |
|---|---|
| Owner | Full control. Cannot be restricted. |
| Administrator | Every permission. Not adjustable under Permissions. |
| Manager | Runs day-to-day document work, plus contacts and reporting. |
| Operator | Sends and handles documents. |
| Viewer | Read-only. |
What each role can do by default
Section titled “What each role can do by default”| Owner | Administrator | Manager | Operator | Viewer | |
|---|---|---|---|---|---|
| View documents | ● | ● | ● | ● | ● |
| Manage documents | ● | ● | ● | ● | |
| Send documents | ● | ● | ● | ● | |
| View templates | ● | ● | ● | ● | ● |
| Manage templates | ● | ● | ● | ||
| View contacts | ● | ● | ● | ● | ● |
| Manage contacts | ● | ● | ● | ||
| View store | ● | ● | ● | ● | |
| Purchase in the store | ● | ● | |||
| Manage billing | ● | ● | |||
| Manage users | ● | ● | |||
| Manage roles | ● | ● | |||
| Manage integrations | ● | ● | |||
| View audit log | ● | ● | ● | ||
| Act as another user | ● | ● | |||
| Permanently delete documents | ● | ● | |||
| View organization analytics | ● | ● | ● | ||
| View individual member activity | ● | ● |
The shape of it: Viewer reads, Operator does the daily work, Manager adds the things that shape how others work — templates, contacts, and reporting — and anything touching money, people or integrations stays with Owner and Administrator.
Changing permissions
Section titled “Changing permissions”Settings → Organization → Permissions — “What each role can do in the organization.” — lets you adjust what Manager, Operator and Viewer can do. Your changes replace the defaults above for your organisation. The tab only appears to the Owner and the Administrator.
Four things you cannot change:
Owner is absolute. The permission system is bypassed entirely for the Owner — every check returns true before any permission is consulted. Restricting the Owner is not possible.
The Administrator has every permission. The Permissions grid only has columns for Manager, Operator and Viewer; the Administrator is not in it, and what they can do cannot be narrowed there.
Managing members is Owner and Administrator only. Even though Manage users appears as a permission, member management is enforced by a direct role check. Granting it to a Manager has no effect — even though the Manager description in the role list talks about managing the team’s users. See Invite people to your organisation.
Seeing an individual’s activity is opt-in. Organisation analytics and individual member activity are deliberately separate:
Seeing that the organization signed 4 820 documents is not the same as seeing that a named person signed 12 of them.
Aggregate analytics never expose who did what. Viewing a named person’s activity has to be switched on explicitly, and is not granted to Manager, Operator or Viewer by default.