Roles & Permissions
Two access levels plus granular per-area permissions, scoped by sub-agency.
Access control keeps staff in the parts of the system they should be in.
Access levels #
Staff have one of two access levels per agency:
- Admin — full access. Never restricted by a permission role.
- Staff — access decided entirely by the permission role you give them.
What only an admin can reach #
A few areas are admin-only regardless of permissions — a non-admin doesn't see them in the navigation and gets an "admin-only" page if they type the URL:
- Team and pending invitations — see Team & Invitations
- Agency Settings — see Agency Settings
- Export your data — see Exporting your data
- Billing — see Billing
- Support tickets — a ticket quotes whatever the reporter pasted into it, so it is kept to the people who already see everything. See Getting help
- Sub-agencies and Permission roles — both decide who exists and what anyone may do, so a permission covering them would only be a slower way of being an admin.
- The three agency-wide dashboards — revenue, analytics and staff performance. Narrowing an agency-wide total to one region would make the number wrong rather than safe, so the whole page is reserved.
Everything else is decided by the permission role, so you can hand out one area — payroll, say, or the compensation plans — without making somebody an admin.
Nobody can change their own access level, admins included. Changes are refused when the target is yourself, on both the Team page and the sub-agency membership list, so a staff account cannot promote itself and an admin cannot lock themselves out by accident.
Granular permissions #
A permission role grants View, Create, Edit and Delete for each area: Talent, Applications, Events, Messaging, Message templates, Documents, Profile photo templates, Statements, Compensation plans, Manager goals, Rewards and missions, Automations, Agency settings and Change history. Sub-agencies and Permission roles are not in the list: both are admin-only for the reason above, so ticking them would have delegated nothing. Two abilities stand on their own:
- Record payouts — marking statements as paid. Separate from editing a statement, so you can let somebody reconcile a month without letting them release the money.
- Manage points — awarding or deducting a host's balance.
A staff member with no permission role can reach nothing, so give everyone a role. Five are created for you:
- Admin — the whole catalogue.
- Manager — runs the day to day: talent, events, messaging, intake forms. Reads payroll but cannot reprice or pay it.
- Recruiter — talent acquisition; no finance at all.
- Customer Service — host communications.
- Analyst — read-only everywhere, finance included.
Only Admin gets Record payouts, Manage points, and write access to compensation plans and agency settings. Hand those out deliberately.
Sub-agency scoping #
Attaching a staff member to a sub-agency carries a permission role of its own and filters their queries to the records of that region. Scoping and permissions are independent: the region decides which records, the role decides what they may do with them.
Multi-agency and super-admin #
A user can belong to multiple agencies (via the agency_user pivot), and
their permission role in one agency grants nothing in another. A platform-level
super-admin can bypass scoping for support. (The super-admin panel is
internal and outside this documentation.)