Overview
Roles & Team is where you manage who has access to your account and what they can do. You'll find it in the Cleeng Dashboard under Admin & Tools > Access & Security > Roles & Team. From here, you invite team members, assign roles, and control access to each of the eight permission areas.
Roles & Team is one of three tabs under Access & Security in Admin & Tools. The other two tabs are covered in separate articles: Setting Up Your Login 2FA Method and Viewing and Exporting Your Audit Log.
Who Can Use This
This section is for anyone with an Owner or Admin Management role, since managing team access is part of that role.
The Owner is the person who created the account. There's only one Owner, and their access can't be limited or removed.
Only the Owner can add or edit other people's access by default. To let someone else do this too, grant them the Admin Management permission.
Everyone else you invite gets access based on the role and permission areas you assign them. Nobody but the Owner has full access by default.
Before You Start
Before you invite anyone to your team, gather a few things so setup goes smoothly.
An Owner or Admin Management Role
Only an Owner or someone with the Admin Management permission can create roles, invite people, and change access settings. If you don't have one of these roles, ask your account Owner to make the change or grant you Admin Management access.
Access to the Invitee's Inbox
Invitations, activation links, and two-factor codes are all delivered by email. Confirm that the person you're inviting has access to the inbox for the address you use.
The Eight Permission Areas
Every role is built from eight permission areas. The table below shows what each one covers and what it allows.
| Permission Area | Access | Allowed Actions |
| Reporting - No PII | Overview, Analytics (without Data Export), ChurnIQ (without Segments) | View, filter, download, and schedule delivery of these reports. Can't access data exports or build ChurnIQ segments. |
| Reporting - Full | Everything under Reporting - No PII, plus Data Export and ChurnIQ Segments | View, filter, download, and schedule delivery of all reports and data exports. Build ChurnIQ segments. |
| Reporting - No Access | None | No access to Reporting. |
| Offer Management | Offers, offer switch settings, gift checkout | Create and manage offers and related settings. |
| Customer Relationship | Customer refunds, coupon management, Hi5 | Manage refunds and coupons. Access Hi5 customer support tools. |
| Customer Accounts | Customer accounts, customer transactions | Access customer and transaction data. Extend access, issue refunds, anonymize customer data. |
| Account Settings | API keys, integrations, Cleeng Custom Fields, company profile, managed users, service status, transactional emails | Manage account-level settings and configuration. |
| Billing - Payout | Payout and Invoice pages, full access | Access and download payout invoices. Change payout bank details. |
| Billing - Invoice | Invoice page only | Access and download invoices. No visibility into payout figures. |
| Admin Management | Roles & Team | Add and edit other admins. Can't edit their own record. |
Reporting Has Its Own Scale
Reporting uses three levels:
- No Access
- No PII
- Full.
Building a Custom Role
You aren't limited to the system roles above. Assign any combination of the eight permission areas to create a role that matches a specific job. When you assign more than one role to a person, the team list shows it as Custom.
Member Types
Every person you add gets a member type, so third-party access is easy to identify:
- Team Member: internal staff at your company. This is the default type for everyday dashboard users.
- Partner: an external agency or integration partner, labeled separately so you can identify third-party access during reviews.
- Cleeng Support: a Cleeng employee invited for time-boxed assistance. This is visible in the team list.
Adding a Team Member
You add someone to your team by sending them an invitation. Here's how:
- Go to Roles & Team and click Add Team Member.
- Enter the person's email address.
- Choose a member type: Team Member, Partner, or Cleeng Support.
- Select the areas this user can access.
- Click Save and Add Next to send the invitation.
You set the member type and permission areas at the time you send the invitation. These take effect the moment the invitee accepts and creates their account.
How an Invitation Moves From Sent to Accepted
An invitation moves through five states:
- Invited: You enter the email, member type, and permissions. No account exists yet.
- Pending: The invitation is single-use and valid for 7 days. The row shows as pending, with the expiration date.
- Resent or Revoked: You can send a new link, which invalidates the previous one, or withdraw the invitation.
- Accepted: The invitee sets their own password, the account is created, and Cleeng records the acceptance in the Audit Log.
- Expired: After 7 days, the link stops working and you need to send the invitation again.
Resending or Revoking an Invitation
To resend or revoke a pending invitation, go to Roles & Team, find the row for that person, and use the options menu next to their entry.
FAQs
Do I need to create an account for a new team member myself?
No. You send the invitation, and the person creates their own account and password when they accept it.
What happens if an invitation isn't accepted in time?
It expires after 7 days and the link stops working. You'll need to send a new invitation.
Why can't I edit my own permissions even though I have Admin Management access?
Admin Management lets you edit other admins' records, but never your own. This prevents someone from removing checks on their own access.