Skip to content

Personal Account Permissions

This page covers the roles and permissions required to manage Personal Accounts.

Admin only

Only users with the Admin user role can manage other users' Personal Accounts (invite new users, edit their user role, assign teams, deactivate, or reactivate). Individual users cannot modify their own user role or team assignments.

User Roles (Workspace-Level)

Action Member Manager Admin
View user list
Invite user
View and revoke invitations
View, configure, and test sign-in providers
Approve or reject identity links
View the sign-in log
Reset own password
Edit user (user role, teams)
Deactivate user
Reactivate user
Enable or disable Qualytics team access (managed deployments)
Generate own Personal Token
Review AgentQ audit history
Comment on a check template's Timeline
Delete another user's comment

Comments on the Timeline

The two rows above are the only comment actions decided by the user role. A check template does not belong to a datastore, so any user can read its Timeline, comment, reply, and manage their own comments. Deleting another user's comment is reserved for the Admin user role, on every asset, and editing another user's comment is never allowed. On containers, quality checks, and anomalies, commenting is gated by team permissions instead: see Team Permissions.

Password recovery requires an existing password account, an enabled Email & Password provider, and working email delivery. See Reset Your Password. Provider administration and the related Access tabs are covered in Sign-In Provider Permissions.

UI Behavior Without Permission

Scenario What the user sees
User has the Member user role Cannot access the Access settings page to manage other users. Can still manage their own Personal Tokens on the Tokens page.
User has the Manager user role Can view the user list and the team list on the Access settings page but cannot edit, deactivate, or reactivate other users.
User has the Admin user role Full access to manage all users: edit their user role, assign teams, deactivate, and reactivate.

The AgentQ audit is also restricted to the Admin user role. Managers can manage the AgentQ integration but cannot open its workspace-wide audit history.

Info

For detailed information about team-level permissions (Editor, Author, Drafter, Viewer, Reporter), refer to the Team Permissions documentation.