Skip to main content
A role defines what you can read and/or write for every resource (such as users, organizations, or businesses) and at which scope that access applies.
Custom Roles AvailableIn addition to the standard roles below, you can create custom roles with granular permissions tailored to your organization’s needs. Learn more in our Custom Roles and Permissions guide.

Quick Reference: Available Roles

RoleIntended forHigh-level capabilitiesPermissions customizable with Custom Roles?
ORG_ADMINClient administratorsManage users and businesses in their organization.
ORG_MANAGERClient users requiring access to the full scope of the organization.Manage users and businesses in their organization.
GROUP_MANAGERClient group managersManage users and businesses inside their group.
BUSINESS_MANAGERClient business managersManage businesses inside their group; limited user management.
PUBLISHERExternal data consumersRead-only access to businesses subscribed to Presence Management.
The ORG_MANAGER, GROUP_MANAGER, and BUSINESS_MANAGER roles can be overwritten with built-in custom roles that provide different permissions. Learn how to configure these in our Custom Roles and Permissions guide.

Detailed Permissions by Role

All permissions listed below assume the user is not using a Custom Role that alters these defaults. For more information about custom roles, see Managing User Permissions with Custom Roles.
Users with the ORG_ADMIN or PUBLISHER role cannot be modified with custom roles.ORG_ADMIN users always have full access to their organization, while PUBLISHER users always have read-only access to locations with an active Presence Management subscription.

Read Access

ResourceScopeDetails
UserOrganizationRead users in the same organization.
OrganizationOrganizationRead your own organization object.
GroupOrganizationRead groups in the same organization.
BusinessOrganizationRead businesses in the same organization.

Write Access

ResourceScopeAllowed actions
UserOrganization• Create users (inherit provider & org_id)
• Update users in the organization
• Assign roles ORG_MANAGER, GROUP_MANAGER, or BUSINESS_MANAGER
OrganizationOrganization• Update the organization itself
Cannot create new organizations
GroupOrganization• Create groups (inherit provider & org_id)
• Update groups in the organization
BusinessOrganization• Create businesses (inherit provider & org_id)
• Update businesses in the organization