Permissions and roles
Klarify uses roles to control what each member can see and do. A member has a role from each of three groups: a user role, an admin role, and a content access role.
User roles
A user role describes how a member relates to your organization.
| User role | Definition |
|---|---|
| Employee | Internal to the organization and linked to an employee record. Can be assigned to positions, which can own and perform documents. |
| Guest | Can only view documents shared directly with them. Does not appear in the organizational structure and cannot be assigned to positions, teams, or departments. |
| Partner | External partner access, managed from the Partners page in settings. Cannot be assigned to positions, teams, or departments. |
Admin roles
An admin role determines which organization-level settings a member can manage.
| Admin role | Definition |
|---|---|
| Account Owner | Full control over the organization, including billing and all settings. Inherits Super Admin rights. |
| Super Admin | Inherits Org Admin and Account Manager rights. Excluded from billing and from managing the organization itself, such as account deletion. |
| Account Manager | Can manage organization settings (name, domain, logo), members, integrations, and API keys. |
| Org Admin | Can manage employees, positions, teams, locations, and departments. |
| Personal Admin | Can manage personal account settings and profile. Available to all member types. |
Content access roles
A content access role controls how much content a member can work with. It is chosen when you invite or create a member.
| Content access | Definition |
|---|---|
| Viewer | Can only view content they have permission to see |
| Editor | Can create and edit content they have permission to edit |
| Global Task Editor | Can edit all task instructions across the organization without gaining edit access to their process models |
| Global Editor | Can edit all process models and task instructions across the organization, including the terms glossary |
Work with task instructions as a Global Task Editor
Global Task Editors can maintain task content wherever it appears. They can update a task’s name, owner, performers, instructions, cover media, attachments, and links. They can also publish a standalone global task or an embedded task instruction independently, and review or restore that task’s history.
This access does not allow someone to change the structure of another person’s process model. A Global Task Editor cannot add, move, resize, reconnect, convert, or remove process elements unless they also have normal edit access to that process model. They also cannot publish the whole process model or change its sharing settings without that access.
Global Task Editor and Global Editor are content access levels, not admin roles. Assigning either one does not grant permission to manage people, organization settings, billing, or other administrative areas.
Content-level access
In addition to role-based access, content-level permissions apply to individual documents. Folders are visible to every active member, but individual documents (process models and global tasks) inside a folder can be restricted. Editors and Viewers need access to a specific document to work with it. Global Task Editors and Global Editors receive the organization-wide content access described above.
See Sharing documentation for how content access roles combine with document visibility, owner and performer assignments, and direct invitations.
Related
- Owners and performers — how accountability and responsibility are assigned on documents
- Sharing documentation — how members receive view or edit access
- How Klarify AI applies your permissions — how these roles work when you connect an AI client