Skip to main content

Permission catalogue

Every permission Level ships with, grouped by section. Use this as the reference when designing roles.

Level ships a fixed set of 14 permissions across two sections. Roles bundle them — you can't add new permissions, but you can mix and match them into any role you want.

The Permissions editor (under Roles & Permissions in Users & Teams) groups them the same way. Two of the permissions are child permissions: they appear nested under their parent in the editor and only make sense together with it.

Roles and Permissions editor with the Owner role selected and permissions grouped in two sections — Administration and Data and Reports
The Permissions editor groups the catalogue into the two sections described below.

Administration

Permissions that reshape the organization itself and control who can access what.

PermissionWhat it grants
Manage Organization SettingsEdit the organization — name, description, logo, reporting currency.
Manage Teams & UsersCreate, edit, delete teams and sub-teams. Add and remove members. Send, resend, and revoke invitations.
Manage RolesCreate, edit, delete roles. Edit role permissions. Apply per-user permission overrides.
Manage Report AccessGrant or revoke access to existing reports via a role's Reports access tab.
Manage Ad Account AccessSet ad-account access levels (No access / Can view / Can control) via a role's Ad accounts access tab.

These are the most powerful permissions. Assign them to leads, admins, and ops people who actually need to reshape the organization.

Data & Reports

Permissions for the day-to-day work — creating and configuring ad accounts, metrics, segments, reports, and content analytics.

PermissionWhat it grants
Create Ad AccountsCreate new ad accounts in the organization.
Manage Metrics & ConversionsConfigure conversion mapping for system metrics; create and edit custom metrics.
Manage SegmentsCreate and edit segments.
Delete SegmentsDelete segments. Child of Manage Segments.
Assign Campaign SegmentsAssign segments to campaigns, including bulk assignment.
Create ReportsCreate and edit reports.
Export ReportsExport reports to Excel.
View Content AnalyticsOpen the SEO/SMM section and read content analytics.
Manage Wire ProjectsConnect a Wire account and link or unlink Wire projects. Child of View Content Analytics.

A typical channel manager role bundles Create Ad Accounts + Manage Segments + Assign Campaign Segments so they can wire up new ad accounts and tag campaigns.

Designing roles around the catalogue

A few patterns that work:

  • Owner — every permission, plus access to every report and ad account. Built-in, protected, held by the organization's owner.
  • Admin — everything in both sections. Effectively Owner without the protection.
  • Channel manager — Create Ad Accounts + Manage Segments + Delete Segments + Assign Campaign Segments + Create Reports; Can control on their ad accounts via Ad accounts access. Can run their channel; can't reshape the organization.
  • Analyst — Create Reports + Export Reports; Can view on the relevant ad accounts. Builds and exports reports without touching setup.
  • Stakeholder / viewer — no permissions at all; specific reports ticked on the Reports access tab. Pure consumption.
  • Content marketer — View Content Analytics + Manage Wire Projects. Runs the SEO/SMM side without ad-platform access.

Build roles around the responsibilities of the people in your organization, not around an idealised hierarchy.