Roles and permissions
The six roles QortexOS offers, what each one covers, and the limits the portal enforces.
Every team member holds at least one role, and roles decide what that person can reach. You set a role when you invite someone, and you change it later from the Roles panel on the Users screen.
The six roles
The portal lists each role with its own description:
| Role | Description in the portal |
|---|---|
| Viewer | Read-only access to tenant data |
| Contributor | Can view and create/update data in assigned areas |
| Team Lead | Team-level oversight and approval authority |
| Manager | Department-level management and approval authority |
| Administrator | Full administrative access to tenant |
| Owner | Tenant owner with full control |
The roles are cumulative. Each role includes everything the roles above it in this table can do, so a Manager can do everything a Team Lead can do, and an Administrator can do everything a Manager can do. Owner has the same reach as Administrator.
A member can hold more than one role at a time. The Roles column on the Users screen shows one label per assigned role.
Who can do what with team management
The portal shows each person only the actions their role allows, so the surest guide is what appears on your own screen. At the level QortexOS discloses on the Users screen:
| Action | Available to |
|---|---|
| View the Users screen, the team members table, and the invitation list | Team Lead and above |
| Edit a member's profile | Manager and above |
| Assign and remove roles | Manager and above |
| Reactivate a member and resend an invitation | Manager and above |
| Invite a member | Administrator and Owner |
| Deactivate a member and revoke an invitation | Administrator and Owner |
Roles reach well beyond team management. The table above describes only this screen. Access to other areas, such as connectors or billing, is granted separately and is not listed on this screen; if an action is missing for you, ask an administrator.
Change someone's roles
Select Roles on their row in the Team members table. The panel is titled "Roles for member name" and it explains: "Grant or remove roles. Changes take effect immediately."
Every role is listed with its description. A role the member already holds carries an Assigned badge. Use Assign to grant a role and Remove to take one away. If you assign a role the member already has, the panel simply tells you it was already assigned and nothing changes.
Limits the portal enforces
Three guardrails apply, and the portal states each one in its own words when you run into it.
- The Owner role cannot be granted or removed here. Owner appears in the roles list, but in place of a button it shows Not assignable. The portal explains this as "The owner role cannot be granted or removed through user management."
- You cannot deactivate your own account. The Deactivate control on your own row is dimmed and does nothing.
- Your organization must keep at least one active administrator or owner. Removing the last one is refused, with the message "The tenant must keep at least one active admin or owner".
Roles are not something you create. QortexOS provides these six, and there is no screen for adding your own.
Related
- Invite team members covers choosing the role at invitation time.
- Manage team members covers profiles, deactivation, and personal settings.