Roles
Roles are groups of permissions that an Administrate User can be assigned to control what they can see and do in the system.
Each User must be assigned at least one Role. Multiple Roles can be combined to reflect a User’s responsibilities across different areas of the application.
For example, a User responsible for both finance and marketing could be assigned both a Finance Role and a Marketing Role.
For elevated access, see Users for details on Super User and Super Company Member.
Table of contents
- Create a Role
- Edit a Role
- Delete a Role
- How permissions behave
- The Restrictions permissions
- Permissions that don't do what their name suggests
- Lookalike pairs to keep straight
- Grants that deserve extra thought
- Permissions Comparison
- Sharing Agreements
Create a Role
- Click +Add Role.
- Select the Company the Role applies to.
- Name the Role (for example: Finance Department, Marketing Manager).
- Add a description explaining its purpose.
- Click Save.
- [Optional] Use the Users tab to assign the Role to Users.
- Go to the Permissions tab.
- Select the permissions to include in the Role (or use Toggle All). Most permissions do what their on-screen name and description say; the rules and the exceptions are covered in How permissions behave below.
- Click Save.
Caution: ensure Administrate Login - Edit is enabled so Users assigned to this Role can log in.
Preview permissions and use Toggle All for faster configuration.
A practical starting point for a new Role: grant Administrate Login - Edit plus the View permissions for the areas the person works in, and add Edit permissions only where they change records.
Edit a Role
- Click the Role you want to edit.
- Make your changes.
- Click Save.
Delete a Role
Note: Users must have at least one Role assigned. Before deleting a Role, ensure affected Users have another Role.
- Click the Role you want to delete.
- Click Delete Role.
- Confirm the action.
How permissions behave
- Permissions are granted per Company. A Role grants each permission for specific Companies, and a User only holds a permission in the Companies it was granted for. Super Users bypass permissions entirely, and a Super Company Member who holds a permission in any Company holds it in all of them — see Users.
- Always include Administrate Login - Edit. Users whose Roles lack it cannot log in at all — this is the most common cause of a new Role "not working."
- View before Edit. Edit and Delete permissions assume the matching View permission is also granted; granting Edit alone does not surface the screens needed to use it.
- Restriction permissions narrow, they don't grant. The Restrictions group filters what a matching View permission shows and does nothing on its own (see below).
- Contact and Account visibility also depends on segregation. With account segregation disabled, Contact - View shows all Contacts regardless of Company. See Company Segregation and Visibility Settings.
The Restrictions permissions
- Event - Restrict To Own limits event and session visibility to events where the User's linked Contact is on the event's personnel list, in any personnel role. It only takes effect alongside Event - View granted for the same Company — on its own it shows nothing — and the User record must be linked to a Contact, or nothing matches. This is the foundation of giving instructors their own restricted login.
- Tasks - Restrict to Own works the same way with Tasks - View, limiting the task list to tasks assigned to the User.
The restriction covers the records the permission names and nothing else: other permissions you grant alongside it (Event Registration - View, Contact - View) still operate at Company level.
Permissions that don't do what their name suggests
| Permission | What it actually controls |
|---|---|
| Companies - View | Cross-Company data visibility — seeing database entries from all operating Companies. Viewing the Company list itself is Company Details - View. |
| Event Administration - View | Evaluation forms, evaluation results and sign-in sheet generation on the event screen — not general event administration. |
| Instructors Report - View | Gates both the Instructors list and the Availability calendar menu item. Withholding it hides the Availability calendar. |
| Delegate Attendance and Results - Edit | Recording attendance and pass/fail results from the event screen. It is independent of Event - Edit — a User can record attendance without being able to change the event. |
| Helpdesk - View | The task list, not a helpdesk. |
| Staff Information - Edit | The Staff checkbox and Supervisor dropdown on a Contact — marking people as staff, not editing staff records generally. |
Lookalike pairs to keep straight
| These two | Differ in |
|---|---|
| Event Registration - View (Events group) and Event Registrations - View (Financial group) | The first shows registrations; the second shows accounts and registrations for an event in financial contexts. Grant deliberately, not by name-matching. |
| Opportunity - View and Opportunity View All - View | Own opportunities versus every User's opportunities. The same pattern applies to Task - View / Tasks View All - View and Message Centre - View / Message Centre - View All. |
| Company Details - View/Edit and Companies - View | Managing the Company list versus cross-Company visibility (see above). |
| Holidays - View/Edit and Own Holidays - Edit | Managing everyone's absences versus a self-service permission scoped to the User's own holidays. |
Grants that deserve extra thought
- User Permissions - Edit lets a User create and edit Roles and allocate permissions — effectively the ability to escalate their own access. Reserve it for administrators.
- Import data - Edit opens the Data Import Tool, which can create and update records in bulk across the instance.
- Sales Receipt Unrestricted Date - Edit allows backdated sales receipts; without it, only the current date is accepted.
- Event P&L - View and Learning Path P&L - View are the single switches that expose margin data on those screens — withhold them from delivery-focused roles such as instructors.
- Automator - Run allows running Automator automations, which act with broad reach across records.
Permissions Comparison
The Permissions Comparison tab allows you to compare Roles and quickly see which permissions are assigned to each.
Use the search field to filter by permission and identify which Roles include it.
Compare Roles and filter permissions for quick analysis.
Sharing Agreements
For organizations operating multiple Companies, Sharing Agreements allow controlled access between them.
Unlike the Super Company Member Role (which grants access to all Companies), Sharing Agreements allow selective access between specific Companies.
You can also grant additional permissions across Companies (for example, allowing another Company to delete Accounts or Contacts).
Create a Sharing Agreement
Sharing Agreements are created from the Company you are currently logged into. You can grant access to your Company’s data, but not configure sharing on behalf of other Companies unless permitted.
- Click +Add Sharing Agreement.
- Select the Company you want to grant access to.
- Add notes describing the agreement (optional but recommended).
- Open the Permissions tab.
- Select the permissions to share.
- Click Save.
The agreement will appear under Shared by You.
Configure cross-company permissions using Sharing Agreements.
View Sharing Agreements
Sharing Agreements are grouped into two tabs:
- Shared By You – Agreements you created to share your data
- Shared With You – Agreements created by other Companies