Skip to main content

Permission catalogue

Every permission Level ships with, grouped by section. Use this as the reference when designing roles.

Level ships a fixed set of 16 permissions across two sections. Roles bundle them — you can't add new permissions, but you can mix and match them into any role you want. Plans that include extra feature areas add their own entry to the catalogue, so the editor may show one or two more than are listed here.

The Permissions editor (under Roles & Permissions in Users & Teams) groups them the same way. Two of the permissions are child permissions: they appear nested under their parent in the editor and only make sense together with it.

The Permissions editor groups the catalogue into the two sections described below.

Administration

Permissions that reshape the organization itself and control who can access what.

PermissionWhat it grants
Manage Organization SettingsEdit the organization — name, description, logo, reporting currency — its notification channels and the branding of its dashboard PDFs. Turn on Telegram posting for a scheduled report.
Manage Teams & UsersCreate, edit, delete teams and sub-teams. Add and remove members. Send, resend, and revoke invitations.
Manage RolesCreate, edit, delete roles. Edit role permissions. Apply per-user permission overrides.
Manage Report AccessGrant or revoke access to existing reports via a role's Reports access tab.
Manage Dashboard AccessSet dashboard access levels (No access / Can view / Can edit / Full access) via a role's Dashboards tab.
Manage Ad Account AccessSet ad-account access levels (No access / Can view / Can control) via a role's Ad accounts access tab.
Manage API ClientsCreate, rotate and revoke the credentials integrations use to read this organization through the public API.

These are the most powerful permissions. Assign them to leads, admins, and ops people who actually need to reshape the organization.

Data & Reports

Permissions for the day-to-day work — creating and configuring ad accounts, metrics, segments, reports, and content analytics.

PermissionWhat it grants
Create Ad AccountsConnect new ad accounts, using up the plan's ad-account allowance.
Manage BudgetsCreate, edit and delete ad-account and campaign targets, the year plan, and which metrics are tracked.
Manage Metrics & ConversionsConfigure conversion mapping for system metrics; create and edit custom metrics.
Manage SegmentsCreate and edit segments.
Delete SegmentsDelete segments. Child of Manage Segments.
Assign Campaign SegmentsAssign segments to campaigns, including bulk assignment.
Create ReportsCreate and edit reports.
Create DashboardsCreate dashboards. Editing an existing one depends on its access level, not on this permission.
Export DataDownload reports and analytics data as Excel or CSV files.
View Content AnalyticsOpen the Wire section and read content analytics.
Manage Wire ProjectsConnect a Wire account and link or unlink Wire projects. Child of View Content Analytics.

A typical channel manager role bundles Create Ad Accounts + Manage Segments + Assign Campaign Segments so they can wire up new ad accounts and tag campaigns.

Designing roles around the catalogue

A few patterns that work:

  • Owner — every permission, plus access to every report and ad account. Built-in, protected, held by the organization's owner.
  • Admin — everything in both sections. Effectively Owner without the protection.
  • Channel manager — Create Ad Accounts + Manage Segments + Delete Segments + Assign Campaign Segments + Create Reports; Can control on their ad accounts via Ad accounts access. Can run their channel; can't reshape the organization.
  • Analyst — Create Reports + Export Data; Can view on the relevant ad accounts. Builds and exports reports without touching setup.
  • Stakeholder / viewer — no permissions at all; specific reports ticked on the Reports access tab. Pure consumption.
  • Content marketer — View Content Analytics + Manage Wire Projects. Runs the Wire side without ad-platform access.
  • Account director — Manage Budgets + Create Reports + Export Data. Owns the money side of a client without being able to reshape the organization.
  • Integrations — Manage API Clients and nothing else. Issues and revokes the credentials a BI tool reads with.

Build roles around the responsibilities of the people in your organization, not around an idealised hierarchy.