Skip to main content
Every teammate you invite is assigned a role that determines exactly what they can see and do in your account. Roles live under User Management > Roles in the left sidebar (/users/user-roles), and the same role list drives the Choose Role dropdown in the Invite Users drawer.
The Roles and Activity items under User Management only appear in the sidebar for accounts with the right plan and permissions — see Custom roles are plan-gated below for what that looks like when they’re hidden.

Default system roles

Every account starts with five built-in roles, plus Full Access — six in total in the role picker:
Choose Role dropdown open, showing Viewer, Billing Manager, Analyst, Manager, Admin, and Full Access as selectable roles

The Choose Role dropdown in the Invite Users drawer, listing all six assignable roles

Selecting a role in the invite drawer shows a live Can / Cannot permission preview for that role. Here’s what each one grants:
Invite Users drawer with Manager selected in the Choose Role dropdown, showing the Manager Role Permissions panel with a green checkmark list of Can items and a red X list of Cannot items

Live permission preview for the Manager role in the invite drawer

Full Access doesn’t show a Can/Cannot preview — selecting it in the invite drawer leaves the permissions panel empty. It’s a separate, unrestricted role distinct from the account Owner (the account you signed up with, which isn’t invited or assigned a role at all).

Viewing a role’s permissions

From the Users table, click the eye icon next to any teammate’s role to open a read-only View User Role drawer. For a default system role, every permission is grouped by category — QR Code, Tags, Analytics, Event Tracking, Integrations, and more — with each individual permission shown as a checked or unchecked checkbox, and a banner confirming the role can’t be edited:
View User Role drawer for the Manager role, with a disabled User Role Name field and a Permissions section reading 'This is a default system role and cannot be edited,' followed by checkbox groups for QR Code, Tags, Analytics, Event Tracking, and Integrations

Read-only view of the built-in Manager role, showing its full permission breakdown grouped by category

Custom roles are plan-gated

Beyond the five default roles, an account can create fully custom roles with its own checkbox-per-permission selection, grouped by the same categories shown above. This is managed from the Roles tab (/users/user-roles), which lists every role — default and custom — with a Create Role button for accounts that have access.
Creating and managing custom roles requires a dedicated quota on your plan. On a test Pro-plan account, the Roles tab is hidden from the sidebar entirely, and navigating directly to /users/user-roles loads an empty page — the component intentionally renders nothing rather than showing a broken table or a 403 error:
User Management > Roles breadcrumb with an entirely blank content area below it, because the account lacks the quota required to view or manage custom roles

The Roles tab on an account without the custom-roles quota: a valid page load with an empty content area, no Create Role button, and no role table

If your plan includes custom roles, expect the Create Role button to open a modal with a name field and the same category-grouped permission checkboxes shown in the read-only view above — just editable instead of disabled. Contact support if you believe your plan should include this and the Roles tab isn’t showing up for you.
  • Shared users — inviting teammates, assigning roles, and managing the Users table.
  • Upgrading your plan — custom roles are plan-gated; upgrading is how you unlock the quota that reveals the Roles tab.