Understanding User Roles
Learn about Understanding User Roles in WaymakerOS.
Learn about Waymaker's 4-tier permission system and what each role can do.
Permission Hierarchy
Waymaker uses a hierarchical permission system where higher roles include all permissions of lower roles:
Account Owner > Organization Admin > Team Admin > User
Role Breakdown
🏢 Account Owner
Who: The person who created the account or was granted ownership
How many: Only one per account
Can transfer: Yes, to any Organization Admin
What they can do:
- ✅ Delete the entire account and all data
- ✅ Transfer ownership to another user
- ✅ All Organization Admin permissions (billing, users, teams)
- ✅ Access all organizations within the account
- ✅ Override any permission restrictions
When to use:
- Primary business owner or CEO
- Technical lead with full platform responsibility
- Legal entity owner for compliance
👑 Organization Admin
Who: Trusted managers who handle day-to-day admin tasks
How many: Multiple per organization
Assigned by: Account Owner or other Organization Admins
What they can do:
- ✅ Manage billing - view invoices, update payment methods, change plans
- ✅ User management - add/remove users, assign license tiers
- ✅ Team management - create teams, assign team admins
- ✅ View all organization data and usage analytics
- ❌ Cannot delete the account or transfer ownership
When to use:
- Department heads and managers
- IT administrators
- HR personnel managing user access
- Finance team members handling billing
👥 Team Admin
Who: Team leads who manage specific groups
How many: Multiple per team (though typically 1-2)
Assigned by: Organization Admins
What they can do:
- ✅ Manage their specific teams - add/remove members
- ✅ Assign team roles - promote members to team admin
- ✅ Access team settings and configurations
- ✅ View team usage and activity
- ❌ Cannot access billing or organization-wide settings
- ❌ Cannot manage users outside their teams
When to use:
- Project managers
- Team leads and supervisors
- Senior team members who recruit others
- Subject matter experts leading initiatives
👤 User
Who: Regular platform users
How many: Unlimited
Default role: Yes, all new users start here
What they can do:
- ✅ Use all core Waymaker features - projects, chat, documents
- ✅ Collaborate within teams they're members of
- ✅ Manage their personal workspace and settings
- ✅ Participate in shared projects and discussions
- ❌ Cannot manage other users or access admin features
- ❌ Cannot view billing or organization settings
When to use:
- Individual contributors
- New team members
- External collaborators or contractors
- Anyone who doesn't need administrative access
Role Comparison Table
| Feature | Account Owner | Org Admin | Team Admin | User |
|---|---|---|---|---|
| Account Management | ||||
| Delete account | ✅ | ❌ | ❌ | ❌ |
| Transfer ownership | ✅ | ❌ | ❌ | ❌ |
| Billing & Licenses | ||||
| View billing dashboard | ✅ | ✅ | ❌ | ❌ |
| Manage payment methods | ✅ | ✅ | ❌ | ❌ |
| Add/remove user licenses | ✅ | ✅ | ❌ | ❌ |
| User Management | ||||
| Invite organization users | ✅ | ✅ | ❌ | ❌ |
| Remove organization users | ✅ | ✅ | ❌ | ❌ |
| Manage team members | ✅ | ✅ | ✅ (own teams) | ❌ |
| Team Management | ||||
| Create/delete teams | ✅ | ✅ | ❌ | ❌ |
| Assign team admins | ✅ | ✅ | ❌ | ❌ |
| Manage team settings | ✅ | ✅ | ✅ (own teams) | ❌ |
| Core Platform | ||||
| Use Waymaker features | ✅ | ✅ | ✅ | ✅ |
| Create projects | ✅ | ✅ | ✅ | ✅ |
| Collaborate on teams | ✅ | ✅ | ✅ | ✅ |
Checking Your Role
In the Interface
- Look at your navigation - Admin features only appear for Organization Admins
- Check permission messages - Error screens tell you what role you need
- View your profile - Your role is displayed in account settings
Permission Error Messages
When you try to access something you don't have permission for, you'll see:
🔒 Access Denied
You don't have permission to access billing information.
Required Role: Organization Admin
Your Role: User
Contact your organization admin if you need access to this feature.
Role Assignment Process
Becoming an Organization Admin
- Current Organization Admin goes to Admin Dashboard
- Finds your user in the User Licenses section
- Upgrades your role using the role controls
- You receive notification and gain immediate access
Becoming a Team Admin
- Organization Admin creates a team (or uses existing)
- Assigns you as team admin during creation or later
- You appear in team management with admin permissions
- Can now manage that specific team
Best Practices
✅ Good Permission Management
- Start everyone as User and promote as needed
- Use Team Admins for department/project leadership
- Limit Organization Admins to trusted business stakeholders
- Regularly audit permissions and remove unused access
❌ Common Mistakes
- Making everyone an Organization Admin "just in case"
- Forgetting to remove access when people change roles
- Not understanding the difference between Team Admin and Org Admin
- Sharing Account Owner access without planning succession
Next Steps: