Personal Account Permissions
This page covers the roles and permissions required to manage Personal Accounts.
Admin only
Only users with the Admin user role can manage other users' Personal Accounts (invite new users, edit their user role, assign teams, deactivate, or reactivate). Individual users cannot modify their own user role or team assignments.
User Roles (Workspace-Level)
| Action | Member | Manager | Admin |
|---|---|---|---|
| View user list | |||
| Invite user | |||
| View and revoke invitations | |||
| View, configure, and test sign-in providers | |||
| Approve or reject identity links | |||
| View the sign-in log | |||
| Reset own password | |||
| Edit user (user role, teams) | |||
| Deactivate user | |||
| Reactivate user | |||
| Enable or disable Qualytics team access (managed deployments) | |||
| Generate own Personal Token | |||
| Review AgentQ audit history | |||
| Comment on a check template's Timeline | |||
| Delete another user's comment |
Comments on the Timeline
The two rows above are the only comment actions decided by the user role. A check template does not belong to a datastore, so any user can read its Timeline, comment, reply, and manage their own comments. Deleting another user's comment is reserved for the Admin user role, on every asset, and editing another user's comment is never allowed. On containers, quality checks, and anomalies, commenting is gated by team permissions instead: see Team Permissions.
Password recovery requires an existing password account, an enabled Email & Password provider, and working email delivery. See Reset Your Password. Provider administration and the related Access tabs are covered in Sign-In Provider Permissions.
UI Behavior Without Permission
| Scenario | What the user sees |
|---|---|
| User has the Member user role | Cannot access the Access settings page to manage other users. Can still manage their own Personal Tokens on the Tokens page. |
| User has the Manager user role | Can view the user list and the team list on the Access settings page but cannot edit, deactivate, or reactivate other users. |
| User has the Admin user role | Full access to manage all users: edit their user role, assign teams, deactivate, and reactivate. |
The AgentQ audit is also restricted to the Admin user role. Managers can manage the AgentQ integration but cannot open its workspace-wide audit history.
Info
For detailed information about team-level permissions (Editor, Author, Drafter, Viewer, Reporter), refer to the Team Permissions documentation.