> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & permissions

> Managing team member roles and permissions.

Every teammate you invite is assigned a **role** that determines exactly what they can see and do in your account. Roles live under **User Management > Roles** in the left sidebar (`/users/user-roles`), and the same role list drives the **Choose Role** dropdown in the [Invite Users drawer](/team/shared-users).

<Note>
  The **Roles** and **Activity** items under **User Management** only appear in the sidebar for accounts with the right plan and permissions — see [Custom roles are plan-gated](#custom-roles-are-plan-gated) below for what that looks like when they're hidden.
</Note>

## Default system roles

Every account starts with five built-in roles, plus **Full Access** — six in total in the role picker:

<Frame caption="The Choose Role dropdown in the Invite Users drawer, listing all six assignable roles">
  <img src="https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/01-role-dropdown-options.png?fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=581c28ff1e8385cd443d9f597eb6e07d" alt="Choose Role dropdown open, showing Viewer, Billing Manager, Analyst, Manager, Admin, and Full Access as selectable roles" width="1440" height="900" data-path="images/v2/team/roles-and-permissions/01-role-dropdown-options.png" />
</Frame>

Selecting a role in the invite drawer shows a live **Can / Cannot** permission preview for that role. Here's what each one grants:

| Role                | Can                                                                                                                                                                                                                                                                       | Cannot                                                                                                                                                                                                       |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Admin**           | Create, design, edit, and delete QR Codes; view and export analytics; create, update, and delete Lead Lists; set up or remove Custom Domains; generate/update/download QR Codes via Bulk Operation; export shared users data; view custom tags; create and manage folders | View or edit billing information; add or remove users; create or remove custom tags                                                                                                                          |
| **Manager**         | Create, design, and edit QR Codes; view and export analytics; set up new Custom Domains; export shared users data; generate/update/download QR Codes via Bulk Operation; create and manage folders                                                                        | Delete QR Codes, Lead Lists, and Custom Domains; view or edit billing information; add or remove users; view custom tags                                                                                     |
| **Billing Manager** | View or edit billing information; upgrade or downgrade the subscription plan; add, update, or remove payment methods; view payment history; download invoices                                                                                                             | View, create, and update QR Codes or Lead Lists; add or remove users; export shared users data; generate/update/download QR Codes via Bulk Operation; view, set up, or remove custom domains and custom tags |
| **Analyst**         | View, download, and export QR Codes data; view and export analytics; view Lead Lists' data & analytics; view the Custom Domain list; view and export shared users data; download QR Codes via Bulk Operation; view custom tags                                            | View or edit billing information; create, design, or edit QR Codes and lead lists; add or remove users; generate or update QR Codes via Bulk Operation; create or remove custom tags                         |
| **Viewer**          | View and export scan analytics/reports; export shared users data; view and export Lead Lists' data & analytics; download QR Codes via Bulk Operation                                                                                                                      | Edit or download QR Codes; view or edit billing information; add or remove users; create or edit Lead Lists; view custom tags                                                                                |

<Frame caption="Live permission preview for the Manager role in the invite drawer">
  <img src="https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/03-manager-permission-preview.png?fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=d38a32ec8d01a996aed4b657f6a40048" alt="Invite Users drawer with Manager selected in the Choose Role dropdown, showing the Manager Role Permissions panel with a green checkmark list of Can items and a red X list of Cannot items" width="1440" height="900" data-path="images/v2/team/roles-and-permissions/03-manager-permission-preview.png" />
</Frame>

<Note>
  **Full Access** doesn't show a Can/Cannot preview — selecting it in the invite drawer leaves the permissions panel empty. It's a separate, unrestricted role distinct from the account **Owner** (the account you signed up with, which isn't invited or assigned a role at all).
</Note>

## Viewing a role's permissions

From the Users table, click the eye icon next to any teammate's role to open a read-only **View User Role** drawer. For a default system role, every permission is grouped by category — QR Code, Tags, Analytics, Event Tracking, Integrations, and more — with each individual permission shown as a checked or unchecked checkbox, and a banner confirming the role can't be edited:

<Frame caption="Read-only view of the built-in Manager role, showing its full permission breakdown grouped by category">
  <img src="https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/00-view-system-role-manager.png?fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=b4f1b01c57a9a53bdfde09982be082fc" alt="View User Role drawer for the Manager role, with a disabled User Role Name field and a Permissions section reading 'This is a default system role and cannot be edited,' followed by checkbox groups for QR Code, Tags, Analytics, Event Tracking, and Integrations" width="1440" height="900" data-path="images/v2/team/roles-and-permissions/00-view-system-role-manager.png" />
</Frame>

## Custom roles are plan-gated

Beyond the five default roles, an account can create fully **custom roles** with its own checkbox-per-permission selection, grouped by the same categories shown above. This is managed from the **Roles** tab (`/users/user-roles`), which lists every role — default and custom — with a **Create Role** button for accounts that have access.

<Warning>
  Creating and managing custom roles requires a dedicated quota on your plan. On a test Pro-plan account, the **Roles** tab is hidden from the sidebar entirely, and navigating directly to `/users/user-roles` loads an empty page — the component intentionally renders nothing rather than showing a broken table or a 403 error:
</Warning>

<Frame caption="The Roles tab on an account without the custom-roles quota: a valid page load with an empty content area, no Create Role button, and no role table">
  <img src="https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=1f105acfa2d2e1b32d129eb5fc3b2f8e" alt="User Management > Roles breadcrumb with an entirely blank content area below it, because the account lacks the quota required to view or manage custom roles" data-og-width="1440" width="1440" data-og-height="900" height="900" data-path="images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=280&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=f10e3204d7ed0ae4a31f324eb54a0d2d 280w, https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=560&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=84e05733dd1ece8f01e88658e2e11ba0 560w, https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=840&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=25c8786935a412a769952ea2d73cd4d8 840w, https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=1100&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=99ad0f8dd945c304f69fc9818a9c4072 1100w, https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=1650&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=e9e1a325fd5cad85abbf60659beb9b05 1650w, https://mintcdn.com/scanova-api/MIBMPA6k9dOWHKMa/images/v2/team/roles-and-permissions/07-roles-tab-locked-blank.png?w=2500&fit=max&auto=format&n=MIBMPA6k9dOWHKMa&q=85&s=a525cea80d74e2159181c311b914b4d0 2500w" />
</Frame>

If your plan includes custom roles, expect the **Create Role** button to open a modal with a name field and the same category-grouped permission checkboxes shown in the read-only view above — just editable instead of disabled. Contact support if you believe your plan should include this and the Roles tab isn't showing up for you.

## Related

* [Shared users](/team/shared-users) — inviting teammates, assigning roles, and managing the Users table.
* [Upgrading your plan](/billing/upgrading) — custom roles are plan-gated; upgrading is how you unlock the quota that reveals the Roles tab.
