For the complete documentation index, see llms.txt. This page is also available as Markdown.

User Roles

Every user has a role and a profile, and the two do different jobs. The role sets the broad kind of access a person has — which portal they sign in to and the overall experience they get. The profile fine-tunes the specific permissions within that role — what they can actually see and do. Understanding the split matters because the role alone never grants detailed permissions; the profile always does.

You set both when you create or edit a user (Settings → Users → Add User), and you manage permission profiles separately in Settings → Profiles.

The five roles

Role
For

Admin

Tenant administrators who configure the platform — catalog, content, journeys, integrations, users, profiles, and settings.

CSR

Customer service reps who work their assigned customer accounts — search, view, assist with subscriptions and orders, and respond to support cases.

Sales

Sales reps who work their assigned customer accounts. Sales is a permission-identical replica of CSR — same portal, same routing, same default access — kept as its own role so sales headcount and access are managed separately from support headcount.

Partner

Resellers and channel partners who manage their assigned customers from the partner portal.

Customer

End customers managing their own account and subscriptions in the customer portal.

The role list is fixed — these five are the only roles. (Customer and Partner users also get an External Account link to a billing account; Admin, CSR, and Sales users do not.)

How the profile fine-tunes the role

Roles are broad; profiles carry the detailed permissions. Each user is assigned exactly one profile, and you can create several profiles per role — for example a CSR Senior profile with refund permissions alongside a CSR Junior profile without them. The same applies to Sales — every tenant starts with a Sales Default profile (an exact copy of CSR Default's permissions); create additional Sales profiles the same way you would for CSR if you need finer-grained variants. When you change a user's role, you reselect their profile, since profiles belong to a specific role.

Gotcha: picking the role is only half the job. A user with the right role but a thin profile may still be missing the permissions they expect — check the profile, not just the role.

See Profiles & Permissions and Portal action permissions.

Last updated

Was this helpful?