Skip to main content
Platform concepts

Roles and permissions

Control who can see and do what — and what the AI is allowed to touch.

Permissions in Ottili ONE govern both your team and the AI. Access is explicit: people and automations only reach what you allow.

Roles

Ottili ONE uses five roles. Roles determine who can view data, change records, manage modules, and approve actions.

RoleScope
Owner*Full control over the company — billing, modules, settings, and team management.
Admin*Invite teammates, manage access, modules, settings, and approvals.
Manager*Manage CRM, inventory, and automation workflows without changing company settings.
Employee*Work inside company modules without changing company-wide settings.
Viewer*Read-only access to company data and modules.

Only Owners and Admins can invite members and change roles. Sensitive operations — approving an action in the approval queue, changing billing, or modifying company settings — require the appropriate role.

AI scope

Ottili AI operates within the permissions you grant. It can only read the tools, data, and modules you connect — and it can never take an approval-required action without a human signing off.

Why it matters

Clear permissions are what make deep AI access safe. The platform's job is to make sure important actions never happen without the right person — or your explicit approval.

For the team-focused walkthrough, see [Company and team](/docs/company-and-team).

Was this article helpful?