Skip to main content

Users & Teams

Organize people in a tree, assign roles, and grant or deny specific permissions per user when needed.

Every organization in Level structures its people as a tree: Organization → Team → Sub-team. Members live on a node of the tree, and the roles attached to that node decide what they can do. For one-off cases — one user needs one extra permission — you can apply a permission override without changing roles.

The page has two columns: an organization tree on the left and a team detail panel on the right with three tabs (Members, Roles & Permissions, and Reports).

Users and Teams page showing the organization tree on the left and the selected unit's detail with members on the right
Organization tree on the left, the selected unit's detail on the right.

The tree

Three node types, three levels — the hierarchy is fixed at three:

  • Organization — the root. The tree always starts at the organization itself.
  • Team — children of the Organization.
  • Sub-team — children of a Team. Sub-teams cannot have further children — three levels is the maximum.

The Organization root is always expanded; teams below collapse and expand on click. Each node shows a small badge with the count of members at that node.

Selecting a node loads its detail view on the right.

What you can do

Create a team or sub-team

With a node selected, click Create team (visible only if you have the Manage Teams & Users permission; on plans below Business the button is locked and reads Create Team · Business). The Create Team modal asks for:

  • Name (required).
  • Description (optional).

Submit creates a child of the selected node — a Team if you were on the Organization, a Sub-team if you were on a Team.

Add members

On the Members tab, click Add member. Two modes:

  • Existing user — search by name or email. Pick the user, then check off one or more roles to assign. Multiple roles per user is allowed.
  • Invite by email — type a new email; Level sends an invitation. Pick exactly one role for the invitee.

Invited people open the invitation link from the email. They have to be signed in with the email the invitation was sent to — Level checks the match. Accepting moves them onto the team with the role you picked. Pending invitations show up on the Members tab with a Pending badge and how long ago they were sent; their row menu has Resend invitation and Revoke invitation — see Invitations.

Adding members is available on Pro and above, up to your plan's member limit. Over the limit you'll see: "This organization's plan allows up to N member(s). Upgrade to add more."

Remove a member

Open the row's overflow menu and choose Remove member. Owners can't be removed this way.

Manage member access

Members have an extra action — Manage access — that opens the access modal. From there you can:

  • Add or remove roles for that user.
  • Open Permission overrides to grant or deny specific permissions for that user only (requires the Manage Roles permission).

Roles

The Roles & Permissions tab is where role definitions live, scoped to the selected node:

  • A list of roles on the left.
  • The selected role's detail on the right with sub-tabs: Members (who has this role), Permissions (what the role grants), Reports access (which reports it opens), and Ad accounts access (which ad accounts it can see or control).

If you don't have the Manage Roles permission, you only see the roles assigned to you. With it, you see every role on this node and can edit them.

Create a role

Create role opens a modal:

  • Name (required).
  • Propagate to child teams — toggle. When on, members holding this role at this team also get it on every sub-team below.

Roles are created with no permissions. Add permissions via the role's Permissions tab.

Edit role permissions

The Permissions tab groups permissions in two sections — Administration and Data & Reports. Each row is one permission with a description and a toggle.

Toggle changes are batched: Save and Discard buttons appear at the bottom once you've made changes. Save commits; Discard reverts.

Reports access and Ad accounts access

Permissions decide what a role can create and configure. Access to reports and ad accounts that already exist is granted separately, on the role's Reports access and Ad accounts access tabs — in batch, across many objects at once. Ad accounts get one of three levels: No access, Can view, or Can control (view plus start/stop sync). See Permissions for the full model.

The Owner role

Each Organization has a special Owner role:

  • Read-only — you can't modify its permissions or remove members.
  • Owner has every permission everywhere by definition.
  • The Permissions tab for Owner shows: "Owner role has all permissions and cannot be modified."

Permission overrides

Click Permission overrides on a member's action menu (requires the Manage Roles permission). The override modal lists every permission with three buttons per row:

  • Default — use whatever the user's roles say (no override).
  • Grant — explicitly give this permission to this user on top of their roles.
  • Deny — explicitly remove this permission for this user, even if their roles include it.

The Effective permissions summary at the top combines roles + overrides into the final answer for the selected user.

Key permissions

Four capabilities gate most of what's covered here:

  • Manage Teams & Users — required to create / edit / delete teams, add or remove members, send invitations.
  • Manage Roles — required to create / edit roles, edit role permissions, apply permission overrides.
  • Manage Report Access — required to grant or revoke access to existing reports from a role.
  • Manage Ad Account Access — required to set ad-account access levels on a role.

Other permissions (creating ad accounts, managing segments and metrics, creating and exporting reports, content analytics) belong to the same catalogue and are assignable to any role you build. See Catalogue for the full list.

Sign-in and invitations

Two related pages live outside this section:

  • Signing up — Level shares one account across Marketing Bar products; sign-up and sign-in happen at accounts.marketing-bar.com. See Signing up.
  • Accept invitation — what an invited user lands on. Renders one of several states (valid, already accepted, expired, not found, signed in with a different email). See Accepting an invitation.

Reports tab

Every unit's detail panel has a third tab: Reports. It's intentionally separate from the global Reports section — it's narrowly about which of the organization's reports this unit's members can open. Access itself is granted from roles (each role's Reports access tab); handing it out requires the Manage Report Access permission.

In this section

  • Organization tree — the three-level hierarchy and how to move between nodes.
  • Teams — creating teams and sub-teams.
  • Members — adding people, managing access, removing.
  • Invitations — sending invitations and how recipients accept them.
  • Permissions — roles, permission catalogue, and per-user overrides.