Administration
Roles
Roles & Permissions controls what each member of your organization can see and do. Every organization starts with five system roles, and you can create custom roles for finer-grained control.
Quick Start
- 1
Review the existing roles
See what each role can do at a glance, including a preview of its top permissions.
- 2
Check the permission matrix
See exactly which permissions are granted per role, broken down by resource — Analyses, Audit, CDC, and more.
- 3
Create a custom role (optional)
Click Create Role if the system roles don't fit — assign it a name and pick exactly which permissions it grants.
- 4
Assign roles to members
Head to Organizations → Team members to assign a role to each person.
System roles
Every organization comes with five built-in roles. System roles can't be deleted, but you can still adjust individual permissions in the permission matrix.
ownerFull access to all resources.adminAdministrative access to manage users, settings, and data.analystCan read data and create analyses. This is the default role for new members.viewerRead-only access to data.memberStandard tenant member: read everywhere, run analyses, upload data.Permission matrix
The matrix lists every resource — Analyses, Audit, CDC, and more — broken down into individual permissions like create, read, update, delete, and execute. A column shows every role; click any cell to toggle that permission for that role. A resource row showsAllwhen a role has every permission under it, or a fraction like 2/3 when it only has some.
- analyst is the default role assigned to new members unless you choose otherwise when inviting them.
- Editing a permission in the matrix applies immediately — there's no separate save step.
- You can search roles by name if your organization has created several custom ones.