Permissions in Ottili ONE govern both your team and the AI. Access is explicit: people and automations only reach what you allow.
Roles
Ottili ONE uses five roles. Roles determine who can view data, change records, manage modules, and approve actions.
| Role | Scope |
|---|---|
| Owner* | Full control over the company — billing, modules, settings, and team management. |
| Admin* | Invite teammates, manage access, modules, settings, and approvals. |
| Manager* | Manage CRM, inventory, and automation workflows without changing company settings. |
| Employee* | Work inside company modules without changing company-wide settings. |
| Viewer* | Read-only access to company data and modules. |
Only Owners and Admins can invite members and change roles. Sensitive operations — approving an action in the approval queue, changing billing, or modifying company settings — require the appropriate role.
AI scope
Ottili AI operates within the permissions you grant. It can only read the tools, data, and modules you connect — and it can never take an approval-required action without a human signing off.
Why it matters
Clear permissions are what make deep AI access safe. The platform's job is to make sure important actions never happen without the right person — or your explicit approval.
For the team-focused walkthrough, see [Company and team](/docs/company-and-team).
Was this article helpful?
