Gorilla Dash

Help Centre

Guides for every part of Gorilla Dash

Step-by-step how-to guides written by the team that builds the product. Read them here, or download any guide as a PDF.

Access & Team Members

Organisation roles

Download PDF

The four roles you start with, building your own, and the permission names that promise less than they grant.

Last updated September 2, 2026


A role is a named bundle of permissions, and it applies to your whole organisation. Every new organisation starts with four, which are yours to edit.

RoleWhat it is
OwnerEverything, always. Cannot be edited or seen in the roles list.
AdministratorEvery permission group in the product.
OperatorEverything operational — but no billing, no user management, no organisation settings.
BillingInvoices, payments, payment methods and quotes only.

Operator is the one most networks should be handing out. It covers the day-to-day work without exposing money or the ability to change who has access.

Only the owner can edit roles

EVEN A FULL ADMINISTRATOR CANNOT CREATE OR CHANGE A ROLE
The ability to create, edit and delete roles is not part of any permission group, so it cannot be granted. In practice that means role changes are done by the organisation owner or by Gorilla Dash support. An administrator can see the roles list but not the controls.

Building your own

Press Create Role, name it, and tick the permission groups. They are arranged in sections by module, and each section has buttons to select or clear it in one go. Assign All Permissions ticks everything.

Use Defaults reloads the permissions from the standard role of the same name — so it works on a role called Operator and does nothing on one called Branch Support.

The Can impersonate tribe users checkbox lets holders sign in as a tribe administrator or team member to see what they see. Give it out sparingly.

Two permission names that mislead

ADD ORGANISATION USER IS NOT "ADD ONLY"
It also carries the ability to edit people's profiles, reset their two-factor authentication, send password resets, detach them from the organisation and — where the role allows it — impersonate them. Treat it as full user administration.
VIEW ORGANISATION USERS ALSO REVEALS THE ROLES SCREEN
Anyone who can see the user list can also see how your roles are configured. They cannot change them, but the structure is visible.

Some permissions are not enforced

DO NOT RELY ON CRM, SMS OR PRINT PERMISSIONS TO RESTRICT ANYBODY
Several permission groups exist in the list but are not currently checked when somebody acts — notably the CRM groups, and every SMS Marketing and Print Marketing group at both organisation and tribe level. Anybody who can reach a tribe can read and write its CRM regardless of what is ticked. Where access genuinely matters, control it by not giving somebody the tribe at all.

CRM export and CRM settings are genuinely gated, so those two are worth setting deliberately.

A note on names

The same capability is sometimes worded differently on the organisation role screen and the tribe permission screen — "View SMS Marketing" in one and "View SMS Campaigns" in the other. They are the same thing.

Next · Access & Team MembersRemoving someone's access