Administration

Roles and permissions

A role is a named set of permissions. Cognify's permissions are fine-grained — twenty-six of them across six groups — so a role can be as broad as an administrator or as narrow as “can read their own tickets and nothing else”.

Every permission

Panel

PermissionAllows
Can create PanelAdding new panels to the workspace
Can update PanelRenaming a panel and changing its icon
Can delete PanelDeleting a panel and everything in it
Can design PanelAdding, changing and removing columns
Can give access to PanelDeciding which members can open the panel

Tabs

PermissionAllows
Can create TabAdding a table, board, graphs or inbox view
Can update TabRenaming a tab
Can design TabChanging what a tab shows — its filter, its status column, its widgets
Can delete TabRemoving a view

Sections

PermissionAllows
Can create SectionSplitting a panel further
Can update SectionRenaming, and running Calibrate
Can delete SectionRemoving a section and its rows

Panel data

PermissionAllows
Can insert Panel DataAdding rows, and importing
Can update Panel DataEditing cells
Can delete Panel DataDeleting rows
Must view only its own Panel DataA restriction, not a grant — the member sees only rows where they are the owner
Must view only its own Panel Data is the one to reach for with contractors, junior agents and clients. It applies everywhere at once — the table, the board, the filters and the charts all narrow, with nothing configured twice.

Automation and integrations

PermissionAllows
Can use IntegrationConnecting and removing mailboxes, channels, webhooks and embeds
Can create AutomationApplying a recipe from the marketplace
Can update AutomationChanging a running automation's values
Can delete AutomationRemoving an automation

Activity

PermissionAllows
Can view ActivityReading a record's timeline
Can create ActivityAdding notes, emails and meetings to a record

Workspace

PermissionAllows
Can manage UsersInviting, editing and removing members
Can manage RolesCreating and changing roles
Can manage StatusManaging user availability states
Can manage SettingsWorkspace preferences, and deleting the workspace
Can approve maker requestReviewing the maker-checker queue

Admin

Admin Access is the master switch — it grants everything above, and admins always have access to every panel regardless of panel access settings.

The create role dialog with the role name at the top and permission groups below, each permission a labelled toggle switch
A role is a name plus a set of switches.

Building a role

  1. Users → Role → new.
  2. Name it after the job, not the person — Support Agent, not Priya.
  3. Leave Active on.
  4. Switch on the permissions it should carry.
  5. Save, then assign it from a member's edit dialog.

Roles worth having

RoleTypically carries
Administrator Admin Access. Keep this to as few people as possible
Manager All panel, tab, section and data permissions, plus automations and integrations — but not workspace management
Agent Insert, update and view activity. No design, no delete, no automation
Restricted agent The same, plus Must view only its own Panel Data
Read only View activity and nothing else — for auditors and observers

Roles and panel access together

These are two different questions, and both must pass:

  • Role — may this person delete rows anywhere?
  • Panel access — may this person open this panel?

A member with delete permission but no access to the Salaries panel cannot delete anything in it, because they cannot open it.

How do I…

Create a role — Users → Role → new → name it, leave Active on, switch on its permissions.

Limit someone to their own records — Give their role Must view only its own Panel Data.

Work out why a button is greyed out — Check the role first (Users → Role), then panel access, then whether Duplicates mode is on — it disables Search, New, Owner and Filter.

Retire a role safely — Move its members to another role first, then deactivate it.