Roles and permissions
Three roles — Admin, Manager and User — at every level. What each one can do in the company, the org, a workspace, a team and a feature.
SeamTrail has three roles. They mean the same thing at every level.
| Role | In one line |
|---|---|
| Admin | Owns the place: its settings, and who is Admin or Manager. |
| Manager | Runs its people and work: brings people in as User or Manager, and removes Users. |
| User | Works in it. |
Four rules
- Rank goes down, not up. A company Admin is Admin of every org in it, and a company Manager is Manager of every org. An org Admin is Admin of every workspace and team in it, and an org Manager is their Manager. A workspace Admin or Manager is the same in every team of that workspace.
- Rank never opens content. Admins and Managers manage people, settings and usage. They do not read a feature's memory unless they are on that feature.
- Your org role and your feature role are separate. A User in the org can be the Admin of a feature they created.
- Only a feature's people can open it. Nobody adds themselves. Someone on the feature adds you.
In the org
| What | Admin | Manager | User |
|---|---|---|---|
| Create a feature (you become its Admin) | ✓ | ✓ | ✓ |
| Connect your own login to a tool the org turned on | ✓ | ✓ | ✓ |
| See your own usage (My usage) | ✓ | ✓ | ✓ |
| Invite people as User or Manager | ✓ | ✓ | — |
| Invite people as Admin | ✓ | — | — |
| Change a person's role | ✓ | — | — |
| Remove a User from the org | ✓ | ✓ | — |
| Remove an Admin or a Manager from the org | ✓ | — | — |
| Turn tools on or off, and connect them, for the whole org | ✓ | ✓ | — |
| Create workspaces and teams | ✓ | ✓ | — |
| Deploy webhook key and deploy rules | ✓ | ✓ | — |
| See the Features list (names, people, usage) | ✓ | ✓ | — |
| See usage per person and per workspace | ✓ | ✓ | — |
| Name an Admin for a feature that has none | ✓ | — | — |
| Read the audit log | ✓ | — | — |
Admins can narrow this
An Admin can leave inviting people, and creating workspaces, teams and features, to fewer people. See Settings. The tables on this page show what applies when nobody changed those settings.
In the company
| What | Admin | Manager |
|---|---|---|
| Admin (or Manager) of every org in the company | Admin | Manager |
| See the Orgs tab with every org | ✓ | ✓ |
| Add an org | ✓ | — |
| Rename the company | ✓ | — |
| Make someone company Admin or Manager, or take it away | ✓ | — |
The company always keeps at least one Admin. Only someone in one of the company's orgs can run the company.
In a workspace or a team
| What | Admin | Manager | User |
|---|---|---|---|
| Open its page | ✓ | ✓ | ✓ |
| Open its Settings | ✓ | ✓ | — |
| Rename it, or delete it (when empty) | ✓ | — | — |
| Create teams in the workspace | ✓ | ✓ | — |
| Bring people in as User or Manager, or invite them by email | ✓ | ✓ | — |
| Bring people in as Admin | ✓ | — | — |
| Change someone's role | ✓ | — | — |
| Remove a User | ✓ | ✓ | — |
| Remove an Admin or a Manager | ✓ | — | — |
| See its usage (workspaces) | ✓ | ✓ | — |
| Read its audit log | ✓ | — | — |
| Change where a team's work lives | ✓ | ✓ | — |
Org Admins and Managers have these rights in every workspace and team as Admin and Manager. See Workspaces and teams.
In a feature
| What | Admin | Manager | User |
|---|---|---|---|
| Open the feature and read its memory | ✓ | ✓ | ✓ |
| Ask the agent about it | ✓ | ✓ | ✓ |
| Add a memory, or mark one as no longer true | ✓ | ✓ | ✓ |
| Mark drift handled, or remove a wrong section link | ✓ | ✓ | ✓ |
| Rename it, change stages, add and remove links | ✓ | ✓ | — |
| Add Users and Managers, and remove Users | ✓ | ✓ | — |
| Promotion rules, suggestions and the Plan | ✓ | ✓ | — |
| See the feature's usage | ✓ | ✓ | — |
| Make someone Admin, or change a role | ✓ | — | — |
| Remove an Admin or a Manager | ✓ | — | — |
Admins of a feature
- The person who creates a feature becomes its Admin.
- A feature always keeps at least one Admin. The last Admin cannot leave. Make someone else Admin first.
- If people leave the org and a feature is left with no Admin, an org Admin names a new Admin from the people still on it.
When someone leaves
When a person is removed from the org, they also leave every feature, workspace and team in the org. Their AI assistants stop working with them.
Invite people
- To the org: the org's Settings → People. Type an email, pick a role, and click Send invite. Someone who already has a SeamTrail login is added right away.
- To a workspace or a team: its Settings → People → Invite by email. Someone new joins the org as a User and the workspace or team with the role you picked. See Workspaces and teams.
- To a feature: the feature's Participants panel. See Features.
People get the right access when they first sign in.