Understanding user roles for organizations
Estimated 3 minute read
You will learn
Learn the difference between organization-level static roles and custom user roles, and how to combine permission sets into a custom organization role.
Static roles
Static roles are fixed personas with a predefined set of access. They cannot be edited or mixed with permission sets.
Role | Description |
|---|---|
Org Super Admin | Full access to the entire organization: org settings, linking/unlinking accounts, requesting accounts for data sharing, billing, user management, and analytics. This is the highest level of permission available, so only grant it to people who need this level of access. |
Org Analyst | Read-only access to reporting. Built for centralized analytics teams and individuals who need visibility into the business without needing to execute. Includes view-only analytics access. Excludes all edit permissions, billing views, and org-level settings. |
Custom user role
Custom roles are built by combining permission sets, and the sub-permissions within them, to fit a specific need. The following sets are available at launch, with more planned for future releases:
Permission set | Sub-permissions | Description |
|---|---|---|
Organization Management | User Management | Add/remove org users, update their roles (scoped to org-specific users only). |
Profile Linking & Consent | Set up and manage data-sharing consent requests, link/unlink accounts to the organization. | |
Billing | Read | View all billing pages. |
Analytics | Read | View all reporting. |
Because Organization Management controls org-level settings for all accounts and users, only grant it to people who should be managing the organization as a whole, not individual brand accounts.