Roles and Permissions

Overview

By default, the email used to create your TheyDo account will be assigned an Admin role.
Admins can invite new users into the TheyDo account and must assign each user two sets of permissions to control both platform access and content editing capabilities.

Organization Roles control account-wide access: user management, billing, integrations, and workspace creation.

Workspace Roles acces to content editing within specific workspaces: which building blocks (journeys, insights, opportunities, etc.) users can create and modify.

Learn how to set up custom roles and permissions here.


Quick Overview- roles and permissions

Organization roles

Organization Roles control platform-wide access like user management, billing, integrations, and workspace creation. To access and adjust Organization Roles, navigate to your settings and click "organization roles".

Default Organization Roles

These are system roles that cannot be modified or deleted. Custom roles can also be created for more granular organization access.

RoleBest ForKey CapabilitiesLimitations
Organization AdminPlatform owners, IT administrators• Full user management • Create workspaces • Access billing & AI & integration settings • Manage all workspaces (public and private)None - full platform access
Organization ViewerStakeholders, cross-team collaborators• View all public workspaces • Comment on content • Can be assigned to workspace roles to gain further accessUnable to edit any content, cannot access private workspaces and cannot manage users or settings

Organization Permissions

Organization Permissions can be assigned to control platform-wide capabilities and administrative functions.

PermissionWhat you can doDefault roles with access
Manage• Full administrative control • Invite users and assign organization roles • Create and configure workspaces • Manage all workspaces (public and private)Organization Admin only
Journey AI• Configure AI settings across the organization • Enable/disable AI features for workspaces • Manage AI dataOrganization Admin only
Integrations• Set up and manage third-party integrations • Configure data connections and synchronization • Manage API keys and integration securityOrganization Admin only
Billing• Manage billing settings and payment methods • View subscription details and usage • Handle plan changes and renewalsOrganization Admin only

Workspace roles

Workspace Roles determine what users can do within individual workspaces in TheyDo. Unlike Organization Roles (which control access to your entire TheyDo account), Workspace Roles are specific to each workspace.

RoleBest forKey capabilitiesLimitations
Workspace AdminProject managers, workspace owners• All content editing • User management • Workspace configuration including taxonomyNone - full workspace access
Workspace EditorCX specialists, journey orchestrators• All content creation/editing • Journey structure control • Create and link building blocksCannot manage users and cannot edit taxonomies.
Workspace ViewerStakeholders, reviewers• View all workspace content • Comment on any content • Export accessible contentCannot create, modify or edit content. Cannot manage users. Cannot edit taxonomies.

These roles are automatically created in new workspaces but can be customized, renamed, or deleted.

RoleBest forKey capabilitiesLimitations
Building Block EditorContent contributors, researchers• Manage insights, opportunities, solutions, metrics, goals, personas • Link content between blocks • Link content to journeysCannot edit journey structure Cannot manage taxonomy Cannot manage users
Product ManagerProduct teams, strategy roles• Manage opportunities, solutions, metrics, metrics, goals • Strategic content focusCannot edit journey structure, personas, or insights Cannot manage taxonomy
Research OwnerResearch teams, analysts• Create and manage insights and metrics • Data-focused contributionsCannot edit other building blocks Cannot edit journey structure Cannot manage taxonomy
Taxonomy OwnerOperations, governance roles• Manage workspace organization • Create status types & tags • Configure workflowsCannot edit journey structure Cannot edit any content Cannot manage users

Workspace Permissions

Permission Scope Levels

Full Access: Create, edit, delete, and manage all aspects of the content type in the workspace

View Only: See content and leave comments, but cannot make changes

No Access: Cannot see or interact with this content type

PermissionWhat you can doDefault roles with access
Manage• Invite users to workspace • Assign workspace roles • Configure workspace settings • Delete or archive workspaceWorkspace Admin
Journey• Create, edit, and delete journeys • Edit journey phases and steps and lanes. • Lock/unlock journeys • Link building blocks to journey steps • Share journeys publicly • Create journey views and filters • Use AI features that generate journey structure from files (requires also Insight permission)Workspace Admin, Workspace Editor
Insight• Create, edit, and delete insights • Link insights to journeys and other blocks • Use AI features that generate insights and quotes (mining, generation) • Upload and manage source filesWorkspace Admin, Workspace Editor
Opportunity• Create edit, and delete opportunities • Link opportunities to journeys and other blocks • Use AI features that reveal opportunities in a journeyWorkspace Admin, Workspace Editor
Solution• Create and manage solutions • Link solutions to journeys and other blocksWorkspace Admin, Workspace Editor
Metric• Create and manage metrics • Link metrics to journeys and other blocksWorkspace Admin, Workspace Editor
Goal• Create and manage goals • Link goals to journeys and other blocks • Track achievement progressWorkspace Admin, Workspace Editor
Persona• Create and manage personas • Link personas to journeys and other blocksWorkspace Admin, Workspace Editor
Taxonomy• Manage workspace taxonomy • Customize statuses, types across building blocks • Configure global tagsWorkspace Admin only

Now that you’ve got the basics down, let’s put it into practice — learn how to set up custom roles and permissions here.

Watch a live example

Continue reading: