Roles & Permissions
Automatum uses role-based access control. Every user in an organization has one role, and that role decides what they can change. Reading is open to everyone in the organization — roles gate who can create, edit, and administer.
Assign roles under Settings > Team. Only an Owner or a Manager can change roles.
The roles
| Role | For | Can do |
|---|---|---|
| Owner | Organization admins | Everything, plus the control plane: assign or remove other Owners, delete the organization, and turn role enforcement on or off. |
| Manager | Team leads / operators | Everything a Manager needs day to day: edit listings and customers, run private offers and co-sell, manage integrations and cloud accounts, and manage users. Cannot delete the organization or manage Owners. |
| Editor | GTM / sales ops | Edit listings and customers, run private offers, and run co-sell. Cannot manage integrations, cloud accounts, or users. |
| Deal Desk | Offer specialists | Create and manage private offers only. |
| Co-sell Manager | Alliance / partner managers | Create and manage co-sell opportunities only (AWS ACE and Azure referrals). |
| Viewer | Stakeholders | Read-only. View everything, change nothing. |
What each role can do
| Capability | Owner | Manager | Editor | Deal Desk | Co-sell Manager | Viewer |
|---|---|---|---|---|---|---|
| View dashboards, listings, offers, co-sell, analytics | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Edit listings & customers | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ |
| Create & manage private offers | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Create & manage co-sell (ACE / Azure) | ✅ | ✅ | ✅ | ❌ | ✅ | ❌ |
| Manage integrations & cloud accounts | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Invite & manage users and roles | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Assign/remove Owners, delete organization | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Rules to know
- Every role can read. Roles only control who can make changes.
- Owner is protected. Only an Owner can assign, change, or remove another Owner.
- You cannot remove the last Owner. Demoting or deleting the sole Owner is blocked, so an organization is never left without one.
- Unknown roles get nothing. A user with no assigned role (or an unrecognized one) is treated as read-only. Access fails closed.
Legacy "Admin"
Organizations created before this model used a single Admin role. Existing Admins are treated as Owners automatically — no action needed.
HubSpot co-sell wizard
When a user opens the co-sell wizard from the HubSpot Deal card, that session can submit co-sell opportunities and private offers on the organization's behalf without a separate Automatum login. It can never manage integrations or users — only the write actions above. See HubSpot Integration.
Assign or change a role
- Go to Settings > Team.
- Click the user.
- Select the new role.
- Click Update Role.
See Organization Management for inviting new members.