Roles and permissions
How access is decided — your role in an org, what your org owns, and what your plan entitles you to.
Three separate questions decide whether a page opens for you. Keeping them apart is what makes the model predictable.
Ownership: is it mine?
Your org's sites, products, flows and agents open for you because your org owns them. Another org's do not, whatever your role. Most manager pages work this way: anyone signed in can reach the page, and it shows the things their org owns.
Role: how senior am I in this org?
Roles are given to members in /org. From least to most:
- Guest — temporary or limited access.
- Member — a regular member.
- Contractor — external, scoped access.
- Staff — regular staff.
- Support — handles tickets and member queries.
- Manager — manages a team or department.
- Admin — full administrative access within the org's sites.
Site-administration pages (users, accounts, payments, the ticket queue) need a senior role. Your role in your own org does not carry over to someone else's site — there you are an ordinary member.
Entitlement: what does my plan include?
Some features are gated by a membership or service level. If a page tells you it needs a plan, see Memberships or the site's upgrade page.
What this means day to day
- A new member of your org can see and edit the org's things according to their role, immediately.
- Giving someone Admin lets them manage users and settings on the org's sites; give it deliberately.
- If a page you expect to open does not, check which org you are acting for (header switcher) before checking your role.