Learn Mokapen

Main menu
Introduction Contact us

Roles and permissions

The role says what that person can do in the organization: invite colleagues, touch settings, see billing, enter the apps. It does not say which cards they see. A private card stays private even for the Owner, unless they are the accountable person, a collaborator, or the author. That rule is in the Data visibility guide. How you invite, how you suspend and how teams work is in the Users and teams guide. Here you choose the right level and understand when a higher level does not fix the problem you have.

The levels, from narrowest to widest, are six: Guest, Limited User, User, Member, Owner, Administrator. You cannot assign a role higher than your own. On the user card the free-text Role field is the job title (consultant, sales manager): it does not change permissions. Permissions are the Permissions menu.

User and Limited User require a Medium plan or higher. Below that plan those two levels cannot be assigned on invite or on edit. Plan names in Mokapen are Free, Small, Medium, Large, Extra Large.

 

Guest

The guest only enters where you put them. On invite you must indicate the projects: all, or a list. Mokapen adds them as a collaborator on those projects. They see tasks and progress of those projects. They do not invite people, do not manage teams, do not open settings, do not import or export, do not see the full address book or billing.

It is the role of the external consultant on a client’s site, or of the supplier who updates tasks on a job. It is the wrong role for an internal colleague who will need to create contacts or deals tomorrow: every new card would have to be shared by hand, and sooner or later someone promotes them in a hurry to the wrong level. If they must work on the organization every day, they are at least a Limited User.

 

Limited User

It is the operational role. They create and update cards in the apps the organization gives them access to (tasks, contacts, deals, tickets, according to the apps that are on). They see users and teams to assign an owner or a collaborator, within the perimeter of their work. They do not invite, do not create teams, do not touch settings, import, export, security or billing.

It requires the Medium plan. It is the right choice for whoever logs time, follows deals or answers tickets and does not need to administer the organization. It is the wrong choice if that person must bring a new colleague in: the invite starts from User upward. Raising them to Member only for an invite also opens import, export and app settings.

 

User

They do everything the Limited User does, and in addition manage users and teams: invite, edit roles not higher than their own, create and arrange teams. They do not change the organization’s general settings, do not import or export in bulk, do not touch security and billing.

It requires the Medium plan. It is the role of a department manager who builds their own team and does not need to decide the plan or custom fields. If they need to add a field or import a CSV, that is Member work, not a reason to make them Owner.

 

Member

They have full access to the CRM and application settings: fields, columns, import and export, operational app preferences. They do not manage billing, do not change the plan, do not edit security (password, two-factor authentication, policy for new cards) and do not delete the organization.

It is the role of whoever configures the CRM for others. A Member can customize contact fields, product list columns, import a file, rename operational details. They cannot turn organization apps on or off, nor open the Security page: those stay with the Owner. If the problem is “I cannot see a private card”, raising their role does not make it appear.

 

Owner

They do what the Member does, and in addition manage security, which applications are active, billing and plans, integrations, any whitelabel, and can delete the organization. They are also the only one who switches a user from Active to Inactive and back, within the plan seat limit.

Keep few of them. An Owner for day-to-day operations is too much: every person with this role can change the plan, turn an app off and touch the policy with which new cards are born. The Owner does not automatically see other people’s private cards. For that you need the lock or Team Master, not this role.

 

Administrator

They have the same permissions as the Owner on the organization, plus the areas reserved for this level: the Partner section, if the organization is a partner, and the Developer section (API and webhooks) when the plan is Large or higher. If you use neither Partner nor Developer, Administrator and Owner are equivalent on a typical day. Do not assign Administrator “to make sure they see everything”: card visibility does not go through here.

 

Comparison

The table is the reminder. The rule that does not fit in a cell: the role opens functions, the lock and collaborators open cards.

FunctionGuestLimited UserUserMemberOwnerAdministrator
Work on assigned cards or indicated projectsYesYesYesYesYesYes
Create cards in enabled appsNoYesYesYesYesYes
See users and teams to assignNoYes, in their own workYesYesYesYes
Invite users and manage teamsNoNoYesYesYesYes
Import, export, fields and columnsNoNoNoYesYesYes
Enable apps, security, billing, delete the organizationNoNoNoNoYesYes
Partner and Developer (Developer from Large plan)NoNoNoNoNoYes

 

Before raising a role

  • If they cannot see a card, check the lock and collaborators, then the users / team filter on the kanban. The report shows everything they can open; the kanban shows their work. It is not a missing permission.
  • If they cannot invite, they need User, not Owner.
  • If they cannot import a CSV or add a field, they need Member.
  • If they cannot change the plan, turn an app off or open Security, they need Owner.
  • User and Limited User on a plan below Medium cannot be assigned: the invite is rejected or the level does not appear.
  • An Inactive user cannot sign in, whatever role they have. An Owner reactivates them, if there is still a seat in the plan.

 

Frequently asked questions

The Owner cannot see a deal. It is private and they are not listed. Add them as a collaborator, add Team Master if the policy provides for it, or make the card public. The role has nothing to do with it.

I set Guest and they cannot find contacts. That is expected. The guest does not have the address book. If they must work contacts, it is Limited User (Medium plan).

Can I give myself a higher role on my own? No. Someone already at that level or above assigns it to you. From the profile, “My roles” updates job title and manager, not the permissions the administrator gave you.

Are Administrator and Owner the same? On the organization yes, except Partner and Developer. Developer requires Large plan or higher.

Need help?