# Roles & Permissions

This page describes the roles and permissions available in Dashboard. Roles are assigned when [creating users](https://developer.incode.com/docs/manage-users#create-users) but can be changed later by [editing the user](https://developer.incode.com/docs/manage-users#edit-existing-users).

***

# Executive

This is the lowest-level role in Dashboard. Users with this role can see and review Sessions they worked on in a single organization.

***

# Executive with Custom Permissions

This role has no default access. You must configure granular permissions for the user based on the sections of Dashboard you want them to access.

Some sections of Dashboard are enabled by feature flags and may not be available for your organization. Contact your Incode Representative with any questions.

The following permissions are available for this role:

| Permission                  | Access Details                                                                                                                                                                                                                                                                                                                                           |
| :-------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ALL                         | Grants full access to every permission listed in this table, as long as the Dashboard section is enabled for your organization.                                                                                                                                                                                                                          |
| users:all                   | Grants access to the [Users](https://developer.incode.com/docs/manage-users) section and all user management functions. Users with this permission cannot modify their own information or role.                                                                                                                                            |
| sessions:all                | Grants access to the Sessions section and all related functions, including the single session view. You can apply **Limited Visibility** to restrict the timeframe for sessions available for the user.                                                                                                                                                  |
| authentications:all         | Grants access to the Authentications section and all related functions. To access Sessions or Identities related to an Authentication, the user must also have **sessions:all** and **identities:all**.                                                                                                                                                  |
| identities:all              | Grants access to the Identities section and all related functions. To access Sessions or Authentications related to an Identity, the user must also have **sessions:all** and **authentications:all**.                                                                                                                                                   |
| flows:all                   | Grants access to create, edit, and delete [Flows](https://developer.incode.com/docs/flows-1). This includes edit access for all modules enabled in the organization.                                                                                                                                                                       |
| custom-watchlist:all        | Grants access to the Custom Watchlist section of Dashboard. The user can view and edit all watchlist entities, manually add an entry to either the Allowlist or the Blocklist, upload a watchlist from their device, or export the watchlist to their device. To create a watchlist entity from an Identity, the user must also have **identities:all**. |
| status:all                  | Grants access to status.incode.com, which shows system operations and any incidents. Users can subscribe to receive updates about outages.                                                                                                                                                                                                               |
| configuration:all           | Grants access to all tabs in the Configuration section.                                                                                                                                                                                                                                                                                                  |
| analytics:all               | Grants access to the Analytics section. The user can view data and metrics on the organization's performance, monitoring, eKYB, and eKYC.                                                                                                                                                                                                                |
| workflows:all               | Grants access to create, edit, and delete [Workflows](https://developer.incode.com/docs/workflows-20). This includes edit access for all modules enabled in the organization.                                                                                                                                                              |
| cms:agent                   | Grants agent-level access to the Case Management section.                                                                                                                                                                                                                                                                                                |
| cms:reviewer                | Grants reviewer-level access to the Case Management section.                                                                                                                                                                                                                                                                                             |
| compliance:all              | Grants access to the Compliance section. This section includes a table view of data added to the system, including new Sessions and Identities. It also includes an audit log of all user activity in the organization. Users can export the audit log to a CSV.                                                                                         |
| escalations:all             | Grants access to the Escalations section. This section shows a table view of escalated Sessions. The table includes the Session ID, the reason for escalation, the escalation status, the Session decision, and more. To access Sessions related to an Escalation, the user must also have **sessions:all**.                                             |
| directory-information:all   | Grants access to the Directory Information section.                                                                                                                                                                                                                                                                                                      |
| integrations:all            | Grants access to the Integrations section.                                                                                                                                                                                                                                                                                                               |
| helpdesk-verifications:all  | Grants access to the Helpdesk Verification section.                                                                                                                                                                                                                                                                                                      |
| candidate-verifications:all | Grants access to the Candidate Verification section.                                                                                                                                                                                                                                                                                                     |

***

# Admin

This role can:

- Access a single organization
- View all sections in dashboard
- Create and edit users with the following roles: Admin, Executive, and Executive with custom permissions

This role cannot:

- Create new organizations
- Create users with the following roles: Super Admin, Integrator, Admin of multiple organizations

***

# Admin of Multiple Organizations

This role grants the same access as the Admin role but allows this access for multiple organizations. When assigning this role, you must select which organizations the user will have admin access to.

***

# Integrator

This role allows a user to create child organizations.

This role can:

- Create and delete child organizations
- Preview all pages from the organization and child organizations
- Create users with the following roles: Admin of multiple organizations, other roles

This role cannot:

- Create users with the following roles: Super Admin, Integrator (will be changed)

<br />
