Skip to main content
A role defines what you can read and/or write for every resource (such as users, organizations, or businesses) and at which scope that access applies.

Quick-reference: available roles

RoleIntended forHigh-level capabilities
ORG_ADMINClient administratorsManage users and businesses in their organization.
GROUP_MANAGERClient group managersManage users and businesses inside their group.
BUSINESS_MANAGERClient business managersManage businesses inside their group; limited user management.
PUBLISHERExternal data consumersRead-only access to businesses subscribed to Presence Management.

Detailed permissions by role

  • Org Admin
  • Group Manager
  • Business Manager
  • Publisher

Read access

ResourceScopeDetails
UserOrganizationRead users in the same organization.
OrganizationOrganizationRead your own organization object.
GroupOrganizationRead groups in the same organization.
BusinessOrganizationRead businesses in the same organization.
CategoryGlobalRead all categories.

Write access

ResourceScopeAllowed actions
UserOrganization• Create users (inherit provider & org_id)
• Update users in the organization
• Assign roles GROUP_MANAGER or BUSINESS_MANAGER
OrganizationOrganization• Update the organization itself
Cannot create new organizations
GroupOrganization• Create groups (inherit provider & org_id)
• Update groups in the organization
BusinessOrganization• Create businesses (inherit provider & org_id)
• Update businesses in the organization
CategoryNot writable