Permission catalogue
Every permission Level ships with, grouped by section. Use this as the reference when designing roles.
Level ships a fixed set of 16 permissions across two sections. Roles bundle them — you can't add new permissions, but you can mix and match them into any role you want. Plans that include extra feature areas add their own entry to the catalogue, so the editor may show one or two more than are listed here.
The Permissions editor (under Roles & Permissions in Users & Teams) groups them the same way. Two of the permissions are child permissions: they appear nested under their parent in the editor and only make sense together with it.
Administration
Permissions that reshape the organization itself and control who can access what.
| Permission | What it grants |
|---|---|
| Manage Organization Settings | Edit the organization — name, description, logo, reporting currency — its notification channels and the branding of its dashboard PDFs. Turn on Telegram posting for a scheduled report. |
| Manage Teams & Users | Create, edit, delete teams and sub-teams. Add and remove members. Send, resend, and revoke invitations. |
| Manage Roles | Create, edit, delete roles. Edit role permissions. Apply per-user permission overrides. |
| Manage Report Access | Grant or revoke access to existing reports via a role's Reports access tab. |
| Manage Dashboard Access | Set dashboard access levels (No access / Can view / Can edit / Full access) via a role's Dashboards tab. |
| Manage Ad Account Access | Set ad-account access levels (No access / Can view / Can control) via a role's Ad accounts access tab. |
| Manage API Clients | Create, rotate and revoke the credentials integrations use to read this organization through the public API. |
These are the most powerful permissions. Assign them to leads, admins, and ops people who actually need to reshape the organization.
Data & Reports
Permissions for the day-to-day work — creating and configuring ad accounts, metrics, segments, reports, and content analytics.
| Permission | What it grants |
|---|---|
| Create Ad Accounts | Connect new ad accounts, using up the plan's ad-account allowance. |
| Manage Budgets | Create, edit and delete ad-account and campaign targets, the year plan, and which metrics are tracked. |
| Manage Metrics & Conversions | Configure conversion mapping for system metrics; create and edit custom metrics. |
| Manage Segments | Create and edit segments. |
| Delete Segments | Delete segments. Child of Manage Segments. |
| Assign Campaign Segments | Assign segments to campaigns, including bulk assignment. |
| Create Reports | Create and edit reports. |
| Create Dashboards | Create dashboards. Editing an existing one depends on its access level, not on this permission. |
| Export Data | Download reports and analytics data as Excel or CSV files. |
| View Content Analytics | Open the Wire section and read content analytics. |
| Manage Wire Projects | Connect a Wire account and link or unlink Wire projects. Child of View Content Analytics. |
A typical channel manager role bundles Create Ad Accounts + Manage Segments + Assign Campaign Segments so they can wire up new ad accounts and tag campaigns.
Designing roles around the catalogue
A few patterns that work:
- Owner — every permission, plus access to every report and ad account. Built-in, protected, held by the organization's owner.
- Admin — everything in both sections. Effectively Owner without the protection.
- Channel manager — Create Ad Accounts + Manage Segments + Delete Segments + Assign Campaign Segments + Create Reports; Can control on their ad accounts via Ad accounts access. Can run their channel; can't reshape the organization.
- Analyst — Create Reports + Export Data; Can view on the relevant ad accounts. Builds and exports reports without touching setup.
- Stakeholder / viewer — no permissions at all; specific reports ticked on the Reports access tab. Pure consumption.
- Content marketer — View Content Analytics + Manage Wire Projects. Runs the Wire side without ad-platform access.
- Account director — Manage Budgets + Create Reports + Export Data. Owns the money side of a client without being able to reshape the organization.
- Integrations — Manage API Clients and nothing else. Issues and revokes the credentials a BI tool reads with.
A person with it can hand a machine credential everything they themselves can see — Level truncates a new client's reach to its creator's at the moment of issue. Only the organization owner can lift that with the all reports / all ad accounts switches. Treat the permission as roughly equal to Manage Report Access, not below it.
Build roles around the responsibilities of the people in your organization, not around an idealised hierarchy.