Alongside the per-item permissions described in Working with permissions, each person has an account role that sets what they can do across the whole workspace.
1. The three account roles
- User – a standard member. They can create, own and be granted access to items, with the per-item permission levels deciding what they can do with each one.
- Company administrator – manages the workspace. In addition to everything a user can do, an admin can manage people, roles and company-wide settings, and can step in on items others control (see below).
- Superuser – a system-level administrator. A superuser's access overrides the normal permission checks, for support and operational tasks.
2. What a company administrator can do
- Manage the company's users and the roles assigned to them.
- Manage workspace-wide settings.
- Force-unlock an item that another user has locked – useful when that person is unavailable.
- Control company-wide sharing – only an admin can grant access to everyone in the company at once.
3. Per-item permissions still apply
Account roles and per-item permissions work together. Being a normal user does not stop you from having Admin permission on items you own or that have been shared with you at that level. Likewise, the per-item levels – Viewer, Operator, Editor, Admin – decide day-to-day access regardless of account role, except that company administrators and superusers can step in where noted above.