Personal Account Permissions
This page covers the roles and permissions required to manage Personal Accounts.
Admin only
Only users with the Admin user role can manage other users' Personal Accounts (invite new users, edit their user role, assign teams, deactivate, or reactivate). Individual users cannot modify their own user role or team assignments.
User Roles (Workspace-Level)
| Action | Member | Manager | Admin |
|---|---|---|---|
| View user list | |||
| Invite user | |||
| View and revoke invitations | |||
| Edit user (user role, teams) | |||
| Deactivate user | |||
| Reactivate user | |||
| Generate own Personal Token | |||
| Comment on a check template's Timeline | |||
| Delete another user's comment |
Comments on the Timeline
The two rows above are the only comment actions decided by the user role. A check template does not belong to a datastore, so any user can read its Timeline, comment, reply, and manage their own comments. Deleting another user's comment is reserved for the Admin user role, on every asset, and editing another user's comment is never allowed. On containers, quality checks, and anomalies, commenting is gated by team permissions instead: see Team Permissions.
UI Behavior Without Permission
| Scenario | What the user sees |
|---|---|
| User has the Member user role | Cannot access the Access settings page to manage other users. Can still manage their own Personal Tokens on the Tokens page. |
| User has the Manager user role | Can view the user list and the team list on the Access settings page but cannot edit, deactivate, or reactivate other users. |
| User has the Admin user role | Full access to manage all users: edit their user role, assign teams, deactivate, and reactivate. |
Info
For detailed information about team-level permissions (Editor, Author, Drafter, Viewer, Reporter), refer to the Team Permissions documentation.