Roles & privileges
Four fixed roles — Viewer, Editor, Publisher, Admin — decide who can create, publish and administer. No custom roles to design, nothing to misconfigure.
The four roles#
| Role | In short |
|---|---|
| Viewer | Read-only access to shared content. |
| Editor | Create & edit content, but cannot publish publicly. |
| Publisher | Create, edit & publish content publicly or to org. |
| Admin | Full access to settings, members & all content. |
The permission matrix#
| Capability | Viewer | Editor | Publisher | Admin |
|---|---|---|---|---|
| View content | ✓ | ✓ | ✓ | ✓ |
| Create & edit content | — | ✓ | ✓ | ✓ |
| Publish publicly | — | — | ✓ | ✓ |
| Manage members | — | — | — | ✓ |
| Manage org settings | — | — | — | ✓ |
What this looks like in practice#
- Viewers browse and open everything shared with the organization, use published apps, and can export CSV from the Data Editor — but see no Upload or Create buttons anywhere.
- Editors upload data, build maps, dashboards, journeys, surveys and layouts, and manage their own items. They can put a survey live for the organization, but not publish anything to the open web.
- Publishers additionally press the Publish button — dashboards, journeys and survey web forms.
- Admins see the Admin area, manage members, roles and settings, and can edit or delete any item regardless of owner.
Assigning roles#
Admins assign roles when inviting or later in Admin → Members. Two things to know: a role change takes effect at the member’s next sign-in, and demoting someone doesn’t orphan their content — items keep their owner, who can read but no longer edit them until re-promoted (admins can always manage them).
Note
Roles are org-wide. There are no per-item permissions beyond the Private/Organization ownership switch — see Sharing & publishing.