Skip to main content
Org Management

Roles and Permissions

The Organization Settings Roles page, Org Admin, Builder, Explorer and Viewer roles, custom roles, how roles add up, and what deleting a role does.

Roles page permission matrix showing roles as columns and permission categories as rows.

Roles are a permission setting in Insight Cloud that controls what each user can see and do across the platform. A role is a named set of permissions, assigned once and reused across users and teams.

You may also see Roles referred to as roles & permissions, user permissions, access levels, user types, or permission groups. Customers often ask about them as "who can do what."

You'll need: The Org Admin role, or the Manage Organization permission, to configure roles. Last reviewed: 2026-10-09

Where to find Roles

Configure roles on the Roles page: Organization Settings → Roles. The Roles page is for users who have the Manage Organization permission. Users without that permission cannot view the Roles page, whatever other roles they hold.

To assign roles to people, go to Organization Settings → Users or Organization Settings → Teams. Roles can be assigned to users and to teams.

What you can do with Roles

  • Assign one or more roles to a user, directly or through team membership.

  • Assign a role to a team, so every member receives it.

  • Create a custom role with the permissions your organization needs.

  • Create a custom role by copying a system role, then adding or removing permissions.

  • Delete a custom role, including one that users currently have (see Deleting a role).

  • Compare roles on the Roles page, which shows a permission matrix: rows are permission categories and individual permissions, columns are roles, and checkmarks show which permissions each role has.

  • Expand or collapse each permission category to focus on one set of permissions.

The system roles in Insight Cloud

Insight Cloud includes four system roles: Org Admin, Builder, Explorer, and Viewer. System roles are the default roles that are available to assign to users and teams. Permissions for each role change over time, so this article describes each system role at a high level. The Roles page shows the current permissions for every role.

Viewer is the baseline role. Viewers consume app outputs and use the consumable parts of the platform, including the App Store, without management permissions.

Explorer is a Viewer with additional capabilities to explore deeper into analysis. Explorers can use the Data Layer, Intelligence, and Explore Mode within an app dashboard, and can generate custom views and configurations tailored to their organization. The Explorer role controls access to Explore Mode in app dashboards.

Builder is a more capable Explorer. Builders can also access the Create area of the platform. This role is mainly for organizations that publish apps on the platform and have technical users who build them.

Org Admin has the Manage Organization designation. Org Admins invite users, create and manage teams, control app permissions, and manage other organization-level settings and configuration.

Permission categories

Permissions on the Roles page are grouped into categories. Examples include:

  • Reports: manage report access and reporting capabilities. Reports permissions govern the My Reports features.

  • User Management: control who can view and manage users.

  • Organizations: manage organization-level settings and configuration.

  • Apps: control app access, embedding, and tagging behavior.

  • Team Management: manage team creation, assignment, and visibility.

Custom roles

An Org Admin, or a user with the Manage Organization permission, can create custom roles. A custom role can include whatever permissions your organization needs. There is no cap on the number of custom roles an organization can create.

System roles cannot be edited or deleted by a user. To change what a system role allows, create a new custom role from a copy of that system role, then add or remove permissions on the copy.

Custom roles are useful for separating operational access from administrative access, supporting different teams (for example Sales, Ops, or Leadership), limiting access to sensitive data or billing features, and keeping access to least privilege.

When you edit a custom role, the change applies immediately to every user assigned that role. Be careful when you change a role that is already in use.

Deleting a role

You can delete a custom role even when users currently have it. System roles cannot be deleted. Before the deletion is processed, Insight Cloud warns the admin that every user who has only that role will be moved to the Viewer system role. The warning appears before anything changes, so the admin can see the effect on those users' experience first.

How Roles combine for a user

Roles are additive. A user's permissions are the sum of every role they hold, whether the role was assigned directly or came through a team.

Roles can reach a user in two ways:

  • Directly: an admin assigns the role to the user.

  • Through a team: the user is added to a team that has a team default role and receives that role. A user can belong to multiple teams and hold multiple roles.

The permissions apply to the user, so the user has the combined permissions of all their roles. A role never adds app access, so these permissions apply to the apps the user already has access to.

When a user leaves a team, they no longer receive the role assigned through that team. When a team's role changes, every user on the team receives the updated permissions as soon as the change is saved.

Examples

A new user is added with the Viewer role. They are then added to a team whose default role is Org Admin. The user inherits the Org Admin role from the team and can fully operate as an Org Admin until they are removed from the team.

A new user is added with the Org Admin role. They are then added to a team whose default role is Explorer. Nothing changes for that user, because Org Admin plus Explorer adds up to the permissions of an Org Admin.

Limits and what Roles can't do

  • Roles do not grant or remove app access. App access is managed separately, for instance through teams.

  • Org Admins have management access to the organization but do not receive app access by default. An Org Admin can grant themselves access to all apps if they need it.

  • Roles can only be assigned to users and teams. A role cannot be assigned to an entire organization at once.

  • System roles cannot be edited or deleted by a user. Copy one into a custom role to change its permissions.

  • Only Org Admins and users with the Manage Organization permission can administer custom roles. Other roles cannot view the Roles page without the Manage Organization permission.

Roles vs. Teams

Roles define what users can do in the platform. Teams define who has what. Teams can have a default role so that its members receive new capabilities automatically. See Teams.

Roles vs. app access

A role does not decide which apps a user can open. App access is granted to users or teams, and a role never adds to it. See Apps and Teams.

The Explorer role vs. Explore Mode

The Explorer Role is a default system role in Insight Cloud. Explore Mode is a feature in app dashboards for deeper exploration capabilities. The Explorer role controls access to Explore Mode. Explore Mode is available to every system role except Viewer. See Explore Mode.

If Roles aren't working

If a user can't see a feature, page, or area of the platform, the likely cause is missing permissions. Contact your organization admin to get the correct permissions. Seek does not decide which permissions customers have on the platform.

If you have a problem creating a custom role or turning on a group of permissions on the Roles page, contact Seek.

Related articles

  • Teams: set a team default role and give app access to many users at once

  • Users: invite users and assign roles when you invite them

  • Administration overview: where organization administration lives

  • Apps: see and manage which apps your workspace can access

  • Explore Mode: the app dashboard feature the Explorer role controls

Was this helpful?

Still need help? Share an idea