Skip to main content
Administration and Security

Role matrix

The complete overview of which of the five Ottili ONE company roles may perform which actions — from team management to approvals and AI permissions.

Overview

Ottili ONE governs access explicitly: people and automations only reach what you allow. The foundation is five company roles — Owner, Admin, Manager, Employee and Viewer. Each role determines who can view data, change records, manage modules and approve actions.

This article summarizes the roles as a matrix. It builds on [Roles and permissions](/docs/roles-and-permissions) and is the same source of truth as the public registry config/product_truth/roles_permissions_audit.yaml. Role assignment itself is a live, production behaviour — not a beta or concept feature.

The five roles

Ottili ONE uses five roles. Their scope is recorded in the public registry and reproduced here unchanged:

RoleScope
Owner*Full control over the company — billing, modules, settings, and team management.
Admin*Invite teammates, manage access, modules, settings, and approvals.
Manager*Manage CRM, inventory, and automation workflows without changing company settings.
Employee*Work inside company modules without changing company-wide settings.
Viewer*Read-only access to company data and modules.

Only Owners and Admins can invite members and change roles. Sensitive operations — approving an action in the [approval queue](/docs/approval-queue), changing billing, or modifying company settings — require the appropriate role.

Permission matrix

The matrix below shows which role holds which permission. ✓ means full access, ◐ restricted (within their own area) and — no access.

PermissionOwnerAdminManagerEmployeeViewer
Invite members & change roles
Change company settings
Activate & manage modules
Manage billing & subscription
Grant approvals in the approval queue◐*◐*
Manage CRM (leads, deals, quotes, orders, invoices)
Manage inventory
Manage automation workflows (Flows)
Use files & modules within granted scope
Read-only access to company data

\* Module-specific approvals may be delegated so a Manager can approve within their responsibility area. Company-wide sensitive approvals remain reserved for Owner and Admin.

Fine-grained permissions and entitlements

The matrix above shows the five base roles. On top of that, granular, module-level rights are controlled by the shared permissions and entitlements system, described in [Shared permissions and entitlements](/docs/shared-permissions-and-entitlements). It defines which concrete actions inside a module (for example Ottili HQ, Ottili Coder or Ottili LD3) are enabled for a role.

The AI within the permission boundary

Ottili AI operates within the permissions you grant. It can only read the tools, data and modules you connect, and it can never take an approval-required action without a human signing off. In practice:

  • A Viewer grants the AI read-only access only.
  • An Employee grants the same write access as their own account — but no administrative rights.
  • Approval-required steps are always escalated to a person for sign-off, regardless of role.

Clear roles are what make deep AI access safe. The platform's job is to make sure important actions never happen without the right person — or your explicit approval.

Related articles

  • [Roles and permissions](/docs/roles-and-permissions)
  • [Approval queue](/docs/approval-queue)
  • [Shared permissions and entitlements](/docs/shared-permissions-and-entitlements)
  • [Security overview](/docs/security-overview)
  • [Secrets management](/docs/secrets-management)
  • [Tenant isolation](/docs/tenant-isolation)
  • [Team administration](/docs/team-administration)
  • [Audit logs](/docs/audit-logs)

Was this article helpful?