Platform · User management
Teams, roles, and permissions
Organize your team by site, department, or function. Control what each role can see and do. Corporate sees everything, sites see their own data.
01User management
Built for multi-site organizations
Different teams need different levels of access and visibility. Pairs with enterprise authentication for end-to-end access control.
Team management
Organize users by site, department, or function. Group team members logically so permissions, notifications, and dashboards align with how your org actually works.
Role-based permissions
Control what each role can see and do, from read-only auditors to full-access administrators. Permissions apply across agents, dashboards, and data.
Multi-site access
Corporate sees everything: trending, benchmarking, and analytics across the fleet. Individual sites see their own data, their own dashboards, their own agents.
02Roles
Five roles, one clear model
Every team member has one of five roles. Roles are assigned per team, so a user can have different roles on different teams within the same organization.
Owner
Full control. Manages billing, creates teams, and has superuser access to all team resources.
Admin
Manages team settings, members, integrations, the operating model, and automated processes.
Editor
Creates and edits records, uses AI features (assist, skills, delegate), and views own history.
Viewer
Read-only access to data and public dashboards. Cannot use AI features or modify records.
Guest
No base permissions. Only sees records explicitly shared via entity-level access grants.
03Granular control
Per-record access overrides
Beyond roles, Authentica supports entity-level access control. Grant or restrict access to individual records regardless of a user's team role, for sensitive data, external collaborators, or cross-team projects. A Guest with Viewer access on a specific shipment can see that shipment and nothing else. Team owners always have full access and cannot be restricted.
01
Admin
View, edit, delete, and manage access for the record.
02
Editor
View, edit, and delete the record.
03
Viewer
View the record only. No modifications allowed.
04
No access
Record is completely hidden from this user.
04Organization-wide
One organization, many teams
The organization owner has superuser access across all teams: view, edit, and manage entities in any team, access billing, and configure organization-wide settings. Cross-team access is automatic and cannot be restricted by team-level settings.
Per-team roles
Same user, different roles on different teams.
Scoped visibility
Each team sees only their own data and agents.
Cross-team analytics
Corporate rolls up trending and benchmarks across the fleet.
Audit trail
Every permission change logged and immutable.
05Governed autonomy
AI access is role-gated
AI features are not available to every role. Assist, Skills, and Delegate require Editor access or above. Automate requires Admin. This is the same governed-autonomy model that runs the rest of the platform: 95% handled autonomously, the uncertain rest escalated, every action logged, by role, the same as everything else.
Assist
Requires Editor+
Conversational AI with full context about your organization, SOPs, and data.
Skills
Requires Editor+
Pre-built capabilities agents can run across workflows and data.
Delegate
Requires Editor+
Assign tasks to agents. Review their work, with the uncertain rest escalated to you.
Automate
Requires Admin+
Deterministic workflows that run the same way every time, no code required.
Who can trigger AI actions?
AI access is role-gated, the same way any other action is. Assist, Skills, and Delegate require Editor access or above. Automate requires Admin. Every trigger, human or agent, passes through the same permission check and lands in the same audit trail: 95% handled autonomously, the uncertain rest escalated, every action logged.
Built for multi-site organizations
See how Authentica handles teams, roles, and permissions across your entire organization. We will configure it to match your structure.