Skip to documentation
Documentation Open Athean (opens in a new tab)

Permissions and roles

Set a shared baseline, give people the permissions their work needs, and delegate sequence access.

Understand how access is combined

An organization administrator manages roles and organization-wide permission settings in Org settings → Permissions.

A person's effective permissions—the actions they can actually take—combine several sources:

  • Default permissions: the baseline granted to everyone in the organization.
  • Assigned roles: permissions from every role assigned directly to the person.
  • Automatic roles: permissions from roles connected to groups they belong to.
  • Individual grants: any permissions already granted directly to that user.

Grants add together. Turning a permission off in one role does not remove access if Default, another role, or an individual grant still provides it. Organization-wide rules can also grant capabilities to everyone.

Administrator access is managed separately through Make admin and Remove admin in User licensing. Custom roles let you grant specific capabilities without making someone an administrator.

Set the baseline for everyone

  1. In Permissions, open the Roles & permissions tab.
  2. Review Org-wide rules. Anyone can edit sequences lets everyone create and edit their own sequence templates and operators. Turn it off when you want those capabilities controlled by roles.
  3. In Role permissions, use Search permissions... to find a capability, or browse the product sections.
  4. Click a cell in the Default column to change the baseline for all users. Click a role's column to change that role's grants.
  5. Select Save changes in the page footer. Use Cancel to discard the pending edits.

Rows marked Org-wide are granted by a rule and cannot be changed independently in the matrix until that rule is turned off. Disable bulk template approval is a separate rule: it prevents bulk approval on the operator approvals page while leaving reject and regenerate actions available.

Matrix edits are staged until saved. Save or cancel them before creating, editing, or deleting a role. The page footer also saves pending changes in the Act on behalf tab.

Create a role for a responsibility

  1. Select Add role.
  2. Enter a Name and an optional Description that explain who should hold the role.
  3. Under Start from, choose Blank or an existing role whose permissions you want to copy.
  4. Select the permissions the role needs. Read the action labels carefully: access to your own items and access to other people's items are separate capabilities.
  5. If the role should follow a team automatically, select the relevant groups under Automatic membership.
  6. Select Create role. To change it later, click its name in the matrix and select Save changes in the role dialog.

For example, use the Live call listening permissions to give a team lead access to Live calls. They do not need full administrator access just to listen to calls.

Maximum owned limits are available for operators and sequence templates. The highest specified limit across the user's grants, roles, and organization default applies. A blank value contributes no limit of its own; it does not cancel a limit supplied elsewhere. If no source specifies a limit, ownership is uncapped. Administrators are exempt from these ownership limits.

Assign roles to people or groups

For an individual assignment, open Org settings → User licensing, find the person, and open their row menu. Select Manage roles, choose their roles, then select Save. A person can hold more than one role.

For a group assignment, edit the role in Permissions and choose groups under Automatic membership. Anyone in any selected group receives the role automatically. Membership follows the group's current resolved members; it is not copied into individual role assignments.

The person's Manage roles dialog lists automatic grants under Held automatically via groups, including their source groups. You cannot remove those grants from the individual role selector. Change the group membership or remove the group from the role instead. Explicit assignments remain separate, so removing someone from a group will not remove a role they also hold directly.

See Groups to set up membership and check its status. If a group's membership refresh fails, its last successful membership remains in use until it resolves successfully again.

Let someone act on behalf of a teammate

Use Act on behalf when someone needs to start or manage sequences for specific sending users.

  1. In Permissions, open the Act on behalf tab.
  2. Use Add user to choose the person who will do the work.
  3. Under Start sequences on behalf of, select the sending users they may enroll contacts for.
  4. Under Manage sequences on behalf of, select the sending users whose sequences they may manage.
  5. Select Save changes. To remove stored access later, remove a sending user from the relevant selection, or remove the row, and save again.

Starting and managing are independent grants. These sequence permissions do not grant authority to send a manual email or complete another user's manual tasks. Both people must be active users in the same organization.

Users already have access to their own sequences. Organization administrators have access to all sending users. For broader delegated access, the role matrix also offers Start sequences for any user and Manage sequences for any user. Removing a stored grant here does not override administrator access or one of those broader role grants.

Review access after a change

Use the role matrix to review what each role grants, and Manage roles to check a person's explicit and automatic assignments. The matrix's user links help find people with matching roles; one role column is not a complete picture of a person's effective permissions.

If someone still has access after a change, check Default, Org-wide rules, their other roles, and their group memberships. If those do not explain it, contact support to review any individual grants. If saving reports a failure, review the message and retry the changes that were not saved; a role can save successfully while its group assignment fails.

To retire a role, open it and select Delete role, then review the confirmation. Deleting it removes that role's grants for everyone who held it; permissions from other sources remain. For disabling a person's Athean access, follow User provisioning.

Still have a question? Talk to the Athean team.