How roles work
- Create a role with a name and description
- Configure permissions (which features are available)
- Set data access scope (how much data is visible)
- Assign the role to employees in the Team section
System roles
System roles cannot be edited or deleted:| Role | Description |
|---|---|
| Owner | Full access to all features and data. Cannot be assigned to employees |
| Admin | Full access to all features and data |
Owner vs Admin
Both roles have full access, but there are important differences:| Aspect | Owner | Admin |
|---|---|---|
| Created | Automatically when agency is registered | Assigned to employees |
| Can be assigned | No | Yes |
| Can be deactivated | No (protected) | Yes |
| Can manage Admins | Yes | No |
| Per agency | 1 | Unlimited |
Default roles
These roles are pre-created for common use cases. They cannot be edited or deleted:| Role | Data access scope | Description |
|---|---|---|
| Creator | Own Data Only | For content creators — access to own accounts, chats, and basic automation |
| Chatter | Own Data Only | For chatters — access to own chats and messaging features |
| Team Leader | Group & Subgroups | For supervisors — can manage team members and view their data |
When to use default roles
- Creator — assign to models who manage their own content
- Chatter — assign to employees who only chat with fans
- Team Leader — assign to supervisors who need to oversee their team
Custom roles
You can create custom roles with specific permissions for your team needs. Custom roles can be edited, deactivated, or deleted.Multiple roles
Employees can have multiple roles assigned. When this happens:Permission combining
All permissions from all roles are combined (union). The employee gets access to everything that any of their roles allows. Example: Employee has Role A (view accounts) and Role B (edit scripts):- Can view accounts (from Role A)
- Can edit scripts (from Role B)
Data access scope merging
When the same permission exists in multiple roles with different scopes, the broadest scope wins:| Scope priority | Level |
|---|---|
| Own Data Only | Lowest |
| Group & Subgroups | Medium |
| All Data | Highest |
- Role A: View accounts with “Own Data Only”
- Role B: View accounts with “Group & Subgroups”
- Result: Can view accounts with “Group & Subgroups” scope
Groups & hierarchy
Employees are organized into groups. Groups form a hierarchy:How groups work
- Each employee belongs to one group
- Groups can have subgroups (up to 6 levels deep)
- Group hierarchy affects what data employees can see
Group restrictions
| Action | Allowed? |
|---|---|
| Delete group with employees | No — move employees first |
| Delete root group | No |
| Move group to different agency | No |
| Create circular hierarchy | No (system prevents) |
Data visibility by group
When a permission has “Group & Subgroups” access level:- Employee sees data from their own group
- Employee sees data from all subgroups below their group
- Employee does NOT see data from parent groups or sibling groups
- Sees Team Alpha data
- Sees Subteam A1 and A2 data
- Does not see Agency (root) data
- Does not see Team Beta data
Who can edit whom
Employees can only edit other employees who are:- In the same group as them, OR
- In a subgroup below their group
- Can edit employees in Team Alpha
- Can edit employees in Subteam A1 and A2
- Cannot edit employees in Agency (root)
- Cannot edit employees in Team Beta
Roles table
| Column | Description |
|---|---|
| Role Name | Name of the role |
| Description | Brief description of the role’s purpose |
| Employees | Who has this role |
| Status | Active or Inactive |
| Actions | Configure, Delete |
Role status
| Status | Description |
|---|---|
| Active | Role can be assigned to employees |
| Inactive | Cannot be assigned to new employees (existing employees keep their permissions) |
Important warnings
Access denied behavior
When an employee doesn’t have permission for a feature:- Menu items are hidden (not shown at all)
- Pages redirect silently to Dashboard
- Buttons and actions are hidden
Scope exceptions
Some features are visible to all employees in the agency regardless of their data access scope:- Custom Proxies — all employees see all proxies
- Roles list — all employees with role management permission see all roles
Next steps
- Managing roles — create, edit, and delete roles
- Configuring permissions — set permissions and data access scopes