A role is a named bundle of permissions, and it applies to your whole organisation. Every new organisation starts with four, which are yours to edit.
| Role | What it is |
|---|---|
| Owner | Everything, always. Cannot be edited or seen in the roles list. |
| Administrator | Every permission group in the product. |
| Operator | Everything operational — but no billing, no user management, no organisation settings. |
| Billing | Invoices, payments, payment methods and quotes only. |
Operator is the one most networks should be handing out. It covers the day-to-day work without exposing money or the ability to change who has access.
Only the owner can edit roles
Building your own
Press Create Role, name it, and tick the permission groups. They are arranged in sections by module, and each section has buttons to select or clear it in one go. Assign All Permissions ticks everything.
Use Defaults reloads the permissions from the standard role of the same name — so it works on a role called Operator and does nothing on one called Branch Support.
The Can impersonate tribe users checkbox lets holders sign in as a tribe administrator or team member to see what they see. Give it out sparingly.
Two permission names that mislead
Some permissions are not enforced
CRM export and CRM settings are genuinely gated, so those two are worth setting deliberately.
A note on names
The same capability is sometimes worded differently on the organisation role screen and the tribe permission screen — "View SMS Marketing" in one and "View SMS Campaigns" in the other. They are the same thing.