Skip to content

Personal Account Permissions

This page covers the roles and permissions required to manage Personal Accounts.

Admin only

Only users with the Admin user role can manage other users' Personal Accounts (invite new users, edit their user role, assign teams, deactivate, or reactivate). Individual users cannot modify their own user role or team assignments.

User Roles (Workspace-Level)

Action Member Manager Admin
View user list
Invite user
View and revoke invitations
Edit user (user role, teams)
Deactivate user
Reactivate user
Generate own Personal Token
Comment on a check template's Timeline
Delete another user's comment

Comments on the Timeline

The two rows above are the only comment actions decided by the user role. A check template does not belong to a datastore, so any user can read its Timeline, comment, reply, and manage their own comments. Deleting another user's comment is reserved for the Admin user role, on every asset, and editing another user's comment is never allowed. On containers, quality checks, and anomalies, commenting is gated by team permissions instead: see Team Permissions.

UI Behavior Without Permission

Scenario What the user sees
User has the Member user role Cannot access the Access settings page to manage other users. Can still manage their own Personal Tokens on the Tokens page.
User has the Manager user role Can view the user list and the team list on the Access settings page but cannot edit, deactivate, or reactivate other users.
User has the Admin user role Full access to manage all users: edit their user role, assign teams, deactivate, and reactivate.

Info

For detailed information about team-level permissions (Editor, Author, Drafter, Viewer, Reporter), refer to the Team Permissions documentation.