# Manage roles

> A role is one or more permission sets that you can assign to any Talon.One [user][manageUsers] and determine what this user has access to.

> For the complete documentation index, see [llms.txt](https://docs.talon.one/llms.txt).

<FeatureAccessInfoBox/>

You can create as many roles as needed. For example, you create roles to ensure only certain
users can edit campaigns in a specific Application or view loyalty programs.

For example, you can [create a role from a template](#create-a-role-from-a-template) called
**Customer Support** that only gives access to coupons and loyalty points in loyalty programs
connected to specific Applications.

:::tip More role examples

- **Growth Manager:** Manager with full access to all Applications and their settings.
- **Campaign Contributor:** Contributor who can create campaigns and
  edit <StateLabel type="disabled" name="Disabled" /> campaigns.
- **UK Marketing Admin:** Admin with full access to country-market Applications and the
  related tools.
- **Seasonal Campaign Manager:** Manager with full access to campaigns and loyalty programs
  in one Application.

:::

If you need help configuring the right roles for your business, contact your Customer
Success Manager.

## Admin role

The admin role is a default role that gives full access to all Applications in your
Talon.One account. With this role, you can access all account features, create and manage
Applications, invite users, and more.

To manage the list of admin users or assign the admin role to a user:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. In the **Roles** section, on the **Admin** role, click <VerticalMenu className="icon"/> > <Edit className="icon"/> **Edit Users**.
1. In **Users**, select which users the admin role is assigned to, and save your changes.

You can also assign the admin role to a user when you invite them, and at any point [from the _Users_ section](#assign-a-role).

## Talon.One support role

The Talon.One support role gives Talon.One users view-only access to your account for
troubleshooting and debugging purposes. The role is automatically assigned to Talon.One support staff.

You have full control over the level of access a Talon.One user has to your account.
For example, if a Customer Success Manager is helping you set up an integration,
you can assign them to the [admin role](/docs/product/account/account-settings/manage-roles.md#admin-role). After the setup is complete, you can assign them to the Talon.One support
role to limit their permissions while still allowing them to see the account. If you need
more advanced help later, you can switch them back to the admin role.

:::note
To [assign a new role](/docs/product/account/account-settings/manage-roles.md#assign-a-role)
to a Talon.One user,
[remove](/docs/product/account/account-settings/manage-roles.md#remove-a-role) the Talon.One support role first.
:::

To view the details of the Talon.One support role:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/>
   **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. In the **Roles** section, click the **Talon.One support** role.

## Create a role

Admins can create roles and assign them to users at any time, including when [inviting new users](/docs/product/account/account-settings/manage-users.md#invite-a-user).

{
<details open>
<summary>Which roles are right for your organization?</summary>

Each role can give access to different areas of the Campaign Manager depending on the
creation mode and selections you make.

See the following comparison table of possible access levels for the  admin role,
 custom role, and {' '}
roles created from a template to find the right roles for your organization.

  
    
      Access level
      Admin
      Application admin
      Manager
      Contributor
      Customer support
      Custom role
    
  
  
    
      Manage organization
      Yes
      No
      No
      No
      No
      No
    
    
      Manage credentials
      Yes
      No
      No
      No
      No
      No
    
    
      Manage tools (Attributes, cart item filters, webhooks, etc.)
      Yes
      Yes*
      No
      No
      No
      Yes
    
    
      Edit user profile
      Yes
      Yes
      Yes
      Yes
      No
      Yes
    
    
      Manage Applications
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      Manage Application settings
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      View campaigns
      Yes
      Yes*
      Yes*
      Yes**
      Yes**
      Yes**
    
    
      Create and edit campaigns
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      Activate campaigns
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      Create campaigns
      Yes
      Yes*
      Yes*
      Yes**
      No
      Yes**
    
    
      Edit inactive campaigns
      Yes
      Yes*
      Yes*
      Yes**
      No
      Yes**
    
    
      Display events
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      Display customers and sessions
      Yes
      Yes*
      Yes**
      No
      No
      Yes**
    
    
      Create and edit coupons
      Yes
      Yes*
      Yes**
      No
      Yes**
      Yes**
    
    
      Create and edit referrals
      Yes
      Yes*
      Yes**
      No
      Yes**
      Yes**
    
    
      Display loyalty programs
      Yes
      No
      Yes*
      Yes*
      Yes*
      Yes**
    
    
      Add and deduct loyalty points
      Yes
      Yes*
      Yes*
      No
      Yes*
      Yes**
    
    
      Manage achievements
      Yes
      Yes*
      Yes*
      Yes**
      No
      Yes**
    
  

*Depends on the Applications selected for the role.
**Depends on the Applications and permissions selected for the role.

</details>
}

### Create a custom role

:::note
To create a custom role, set permissions for at least one Application or one loyalty
program.
:::

To create a role from scratch:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. On the right side of the **Roles** section, click **Create Role**, and select **Custom Role**.
1. In **Role name**, enter a name for the role.
1. In **Description**, enter a description to help users understand the purpose of the role.
1. In **Application permissions**, select one or more Applications for which you want to set permissions.
1. Select the permission for each Application [entity](/docs/dev/concepts/entities/entities-overview.md)
   in the list:
   - **Create and edit:** Can create new entities and edit them.
   - **View only:** Can only view the entity.
   - **No access:** Cannot access the entity.

    :::note
      - The selected permissions are also applicable to [templates](/docs/product/campaigns/templates/overview.md) and [campaigns from templates](/docs/product/campaigns/create-and-manage-campaigns.md#create-a-campaign-from-a-template).
      - Selecting the **Create and edit** permission for campaigns automatically enables it for campaigns from templates as well.
      - To create a different set of permissions for another Application, click **Add Permission Set**.
      - You cannot create two roles with the same combination of permissions and Applications.
    :::

1. In **Loyalty program permissions**, select one or more loyalty programs and set the
   permission for each program:
   - **Manage:** Can fully manage the loyalty program.
   - **Support:** Can add and deduct loyalty points.
   - **View:** Can only view the loyalty program.

1. In **Account permissions**, select the account-level permissions for this role:
   - **Create and edit:** Can create new entities and edit them.
   - **View only:** Can only view the entity.
   - **No access:** Cannot access the entity.

   :::note
   These permissions apply to all achievements, giveaways, rewards, audiences, tools, and logs, irrespective of the role's Application and loyalty program permissions.

   For example, if the role has **View only** permission for logs, a user assigned to this role can view all logs, even for Applications where their permission is set to **No access**.
   :::

1. (Optional) In the **Users** section, select one or more users you want to assign this
   role to.

    :::tip
    You can assign a role to users when you [edit the role](#edit-a-role), when you
    [invite new users](/docs/product/account/account-settings/manage-users.md#invite-a-user),
    or at any point [directly from the _Users_ section](#assign-a-role).
    :::

1. Click **Create Role**.

### Create a role from a template

To create a role from a template:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. On the right side of the **Roles** section, click **Create Role** and select one of the
   available templates:
   - **Application Admin:** Has full Application access.
   - **Manager:** Has full access to campaigns, campaign templates, and loyalty programs.
   - **Contributor:** Has limited access to campaigns, campaign templates, and loyalty programs.
   - **Customer Support:** Has access to coupons and loyalty points.

    :::tip
    We recommend assigning permissions in the following ways for effective access control over your campaigns:
    - Create and edit all campaign templates: Assign to users with higher permission levels, for example, Growth Managers.
    - Create and edit only campaigns from templates: Assign to _Contributor_ roles to limit access.
    :::

1. Modify the name and description of the role as needed.
1. In **Application permissions**, click <Add className="icon"/> and select one or more
   Applications for which you want to set permissions.
1. (Optional) Deselect permissions from the list to further customize the permission set.

    :::note
      - To add a different set of permissions for another Application, click **Add Permission Set**.
      - You cannot deselect permissions in the _Application Admin_ template.
      - When you deselect a permission in the _Manager_ template, it becomes a view-only
        permission. Some _Manager_ permissions are connected and cannot be deselected separately.
      - If you switch to another template after customizing the permissions, the list of
        preselected permissions is reset.
      - You cannot create two roles with the same combination of permissions and Applications.
      - The role gives permissions by default to all loyalty programs connected to the
        Applications selected in the previous step. If you select one or more loyalty
        programs while [editing the role](/docs/product/account/account-settings/manage-roles.md#edit-a-role),
        the role gives access only to those programs.
    :::

1. (Optional) In the **Users** section, select one or more users you want to assign this
   role to.

    :::tip
    You can assign a role to users when you [edit the role](#edit-a-role), when you
    [invite new users](/docs/product/account/account-settings/manage-users.md#invite-a-user),
    or at any point [directly from the _Users_ section](#assign-a-role).
    :::

1. Click **Create Role**.

## Manage permissions

When a user has multiple roles and is in [campaign access groups](/docs/product/account/account-settings/manage-campaign-groups.md) for an Application, the highest permission level takes priority. This means that role permissions override campaign access group permissions. If a user has [multiple roles](/docs/product/account/account-settings/manage-roles.md#multiple-roles) for the Application, the role with the highest access level takes priority.

### Roles and campaign access groups

If a user has a role that allows them to view all campaigns in an Application, they keep
that access even if they are in a restricted [campaign access group](/docs/product/account/account-settings/manage-campaign-groups.md).

:::tip
 To limit a user to specific campaigns in an Application, [remove the role](/docs/product/account/account-settings/manage-roles.md#remove-a-role) and add the user to a [campaign access group](/docs/product/account/account-settings/manage-campaign-groups.md) instead.
 :::

Consider, for example, an Application for the European market with two teams, one for France and one for Germany. You can provide different levels of access for the two teams as follows:

- Full access: To allow a user, such as a regional manager, to oversee both teams,
  [assign an Application-level role](/docs/product/account/account-settings/manage-roles.md#assign-a-role).
  This grants full visibility across all campaigns.

- Restricted access: To limit a user, such as a local manager, to the France team,
  do not assign an Application-level role. Instead, manage their access exclusively by
  [adding them to the France campaign access group](/docs/product/account/account-settings/manage-campaign-groups.md#add-users-to-a-campaign-access-group).

### Multiple roles

If a user has multiple roles, they always receive the highest level of permissions
granted by any one of them. In this case, the _Create and edit_ permission overrides the
_View_ permission.

Consider, for example, a user with two roles for the same Application:

- **Role 1:** _Campaign Contributor_ for the _My E-shop_ Application.
- **Role 2:** _Coupon Manager_ for the _My E-shop_ Application.

The table below shows the permissions for each role and the user's final permissions for this Application:

|          Entity          | Role 1 permissions | Role 2 permissions | Final permissions |
| ------------------------ | ------------------ | ------------------ | ----------------- |
| Campaigns                | View               | View               | View              |
| Rule Builder             | View               | View               | View              |
| Coupons                  | View               | Create and edit    | Create and edit   |
| Referrals                | View               | View               | View              |
| Insights                 | View               | View               | View              |
| Campaign settings        | View               | View               | View              |
| Campaigns                | Create and edit    | View               | Create and edit   |
| Campaign evaluation      | View               | View               | View              |
| Customers and sessions   | View               | Create and edit    | Create and edit   |
| Events                   | View               | View               | View              |
| Application settings     | No access          | View               | View              |
| Templates                | View               | Create and edit    | Create and edit   |
| Campaigns from templates | Create and edit    | View               | Create and edit   |

## Display roles

In <Account className="icon"/> **Account** > <Org className="icon"/> **Organization** >
**Users and Roles**, the **Roles** section displays the roles in your account.

Each role card displays the following information:

- Role name
- Role description
- <User className="icon"/> Number of users the role is assigned to
- <Apps className="icon"/> Number of Applications connected to the role

## Assign a role

You can assign a role to one or more users at any time. You can do this when [creating](#create-a-role)
or [editing a role](#edit-a-role), when [inviting a new user](/docs/product/account/account-settings/manage-users.md#invite-a-user), or directly from the _Users_ section.

To assign a role from the _Users_ section:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. In **Users**, to the right of the user you want to assign the role to, click <VerticalMenu className="icon"/> > <User className="icon"/> **Assign Role**.
1. In the menu that appears, select the role you want to assign. You can select more than
   one role.

   :::important
   Admins have full account access and cannot have other roles. Assigning another role to
   an admin user revokes their admin permissions.
   :::

## Remove a role

You can remove an assigned role from any user at any time. You can do this when [editing a role](#edit-a-role) or directly from the _Users_ section.

To remove an assigned role in the _Users_ section:
1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Open <Org className="icon"/> **Organization** > **Users and Roles** > **Users**.
1. In **Users**, select a user from the table. Alternatively, use the search bar to find a user by name or email address.
1. In the **Roles** column, click **X** next to the role name to remove it.
1. Click **Remove Role**.

## Edit a role

You can update a role's name and description, add or remove Applications, update its
permissions, and change the list of users the role is assigned to at any time. The effect
is immediate.

To edit a role:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. In the **Roles** section, on the role you want to edit, click <VerticalMenu className="icon"/> > <Edit className="icon"/> **Edit Role**.
1. Edit the role details, selected Applications, or users assigned to this role and click **Save**.

## Delete a role

:::important
You can delete a role at any time. This action cannot be undone. When a user is assigned
only one role, and you delete that role, the user loses access to all Applications.
:::

To delete a role:

1. In the lower-left corner of the Campaign Manager, click <Account className="icon"/> **Account**.
1. Click <Org className="icon"/> **Organization** > **Users and Roles**.
1. In the **Roles** section, on the role you want to delete, click <VerticalMenu className="icon"/> > <Delete className="icon"/> **Delete Role**.
1. In the pop-up that appears, click **Delete Role**.

## Related pages

- [Manage users][manageUsers]
- [Application overview](/docs/product/applications/overview.md)

[manageUsers]: /docs/product/account/account-settings/manage-users.md
