Roles and what each one can do
The four roles, what each can see and change, and how to choose between them.
On this page
Four roles. Most people should be an Officer.
| Role | Can see | Can change |
|---|---|---|
| Officer | Cases in their teams | Their own cases; act on gated approvals assigned to them |
| Supervisor | All cases in their teams | Team cases, reassignment, approvals for their teams |
| Administrator | All cases | Case types, workflows, autonomy levels, people, integrations |
| Auditor | All cases, read only | Nothing |
Choosing
Officer is the default. It is the role for someone who works cases.
Supervisor is for someone accountable for a queue rather than a case. The distinguishing question is not seniority — it is whether they need to reassign other people's work.
Administrator changes the rules everyone else operates under, including autonomy levels. Keep the number small and name them; the audit log records who changed what, and that is more useful when the list is short.
Auditor sees everything and can change nothing, including its own role. Intended for internal audit, external inspection and anyone who needs assurance without needing access.
Teams decide visibility, roles decide capability
This is the part people get wrong. A role says what someone can do; a team says which cases they can see. An Officer in no teams sees nothing. A Supervisor in one team supervises that team only.
To give someone access to a case outside their teams, add them to the case rather than widening their role.
Changing a role
Settings → People, select the person, change the role. It takes effect immediately, including for a signed-in session — a narrowed role applies on their next action, not their next login.