> ## Documentation Index
> Fetch the complete documentation index at: https://docs.go.aiinsurance.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & permissions

> Understand how roles and permissions control access, create custom roles, change what a role can do, move members between roles, and keep roles built from a template up to date.

Every member of your company, and every API key, holds exactly one **role**. A
role is a named bundle of **permissions**, and a permission is one action on
one kind of record: *View policies*, *Bind a quote*, *Approve an invoice*.
Whatever a role doesn't permit simply doesn't appear in the app — buttons,
menu items, and whole admin tabs are hidden rather than disabled.

The **Roles** tab of the admin area is where roles are created, edited, and
deleted. Open it by selecting your **company name** at the bottom of the left
sidebar, then the **Roles** tab.

<Note>
  Any role that can view roles sees this tab — every standard role except
  **Client Member**. Creating, editing, and deleting roles needs the *Manage
  roles* permission, which only the **Admin** role holds. Other roles see the
  message *"You can view this role but not change it. Only an Admin can edit
  roles."*
</Note>

## How roles work

* **Roles belong to your company.** Each company has its own set of roles.
  Changing a role here changes it for this company only, and if you belong to
  several companies you hold a separate role in each.
* **Standard roles are copies of a template.** Every company starts with the
  same eight [standard roles](#the-standard-roles), each copied from a template
  AI Insurance maintains. A standard role you haven't touched stays **In
  sync** with its template and picks up new permissions automatically.
* **Custom roles are yours.** Create one from scratch or by copying another
  role, or edit a standard role — the moment you do, it becomes **Customized**
  and stops changing on its own. See [Keep up with template
  changes](#keep-up-with-template-changes).
* **Admin is locked.** It always holds every permission, can't be edited or
  deleted, and is the only role that can manage roles. See [The Admin
  role](#the-admin-role).

## The Roles tab

The table lists every role in your company: the eight standard roles first,
then your custom roles alphabetically.

| Column                     | Meaning                                                                                                                                                                                                                                                                       |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Role**                   | The role's name, with its description underneath.                                                                                                                                                                                                                             |
| **Members** / **API keys** | How many users and keys currently hold the role.                                                                                                                                                                                                                              |
| **Origin**                 | **Template** — this company's copy of a standard template. **Custom** — this company's own role; it follows no template.                                                                                                                                                      |
| **State**                  | **Locked** — always every permission, not editable (Admin only). **In sync** — untouched; receives new template permissions automatically. **Customized** — edited away from its template; new template permissions arrive as a notice instead. A custom role shows no state. |

<Frame caption="The Roles tab: every role in your company with its origin and state.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/roles-table.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=0d33036c9c5ffecf95b79cb2ab693bb4" alt="The admin Roles tab listing Admin, Manager, Viewer, Client Member, Captive Manager, Claims Adjuster, Underwriter and Finance, each with a description, Members and API keys counts, a Template origin pill, and a Locked or In sync state pill, with a New role button at the top right." width="1440" height="900" data-path="assets/app/admin/roles-table.png" />
</Frame>

A **+N new** marker beside the state means the role's template has gained
permissions the role doesn't hold yet — open it to review them.

<Frame caption="A customized Manager role with one new template permission waiting for review.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/roles-table-new-permissions.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=8f7c26a9946852b13d7853e59f0d7c51" alt="The Roles tab where the Manager row shows a Customized state pill and a +1 new marker beside it, while the other template roles still show In sync." width="1440" height="900" data-path="assets/app/admin/roles-table-new-permissions.png" />
</Frame>

Select any row to open the role. The **New role** button at the top right of
the card appears only for roles that can manage roles.

## The standard roles

| Role                | What it allows                                                                                                                                                                                                                    |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Admin**           | Full access to everything in the company, including members, roles, API keys, and configuration. Cannot be edited or deleted.                                                                                                     |
| **Manager**         | Runs the business day to day: every submission, quote, policy, claim, invoice, file, and form. Does not manage members, roles, API keys, company settings, or configuration, and does not approve invoices or edit paid invoices. |
| **Viewer**          | Sees everything, changes nothing. Can download files and forms and export any list.                                                                                                                                               |
| **Client Member**   | Views and downloads the company's shared files — nothing else.                                                                                                                                                                    |
| **Captive Manager** | Sees everything and manages the company's files: upload, edit, delete.                                                                                                                                                            |
| **Claims Adjuster** | Handles claims end to end: opens, edits, closes, and reopens events, sets reserves, and enters claim payments for approval. Never approves, voids, or pays invoices.                                                              |
| **Underwriter**     | Works submissions through to bound policies: rates and binds quotes, issues forms, imports submissions, and runs policy transactions.                                                                                             |
| **Finance**         | Keeps the books: creates, approves, finalizes, and voids invoices, records and sends payments, manages payees, and imports financial history.                                                                                     |

Captive Manager, Claims Adjuster, Underwriter, and Finance all build on
Viewer: they can see everything and change only their own area. Open any role
to see its exact permission list.

## Create a role

<Steps>
  <Step title="Select New role">
    The **New role** button sits at the top right of the Roles card.
  </Step>

  <Step title="Name it and pick its starting permissions">
    Enter a **Role name** and an optional **Description** — both appear in the
    role picker when you invite users, so describe who the role is for.

    **Starting permissions** decides what the role begins with: **None —
    start empty**, or a copy of any existing role's permissions, standard or
    custom. Copying **Admin** is allowed and gives you an ordinary, editable
    role with every permission ticked.
  </Step>

  <Step title="Select Create role">
    The role is created as a **Custom** role and opens in the editor, where you
    can adjust its permissions before anyone is assigned to it.
  </Step>
</Steps>

<Frame caption="The New role dialog: name, description, and which role's permissions to start from.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/new-role-dialog.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=1300eab1c1ef8f1198fadc9370c863c1" alt="The New role dialog with Role name set to Event Manager, a description, and the Starting permissions dropdown open listing None — start empty followed by each standard role marked Template." width="1440" height="900" data-path="assets/app/admin/new-role-dialog.png" />
</Frame>

<Tip>
  Start from the standard role closest to what you need, then remove
  permissions. For example, a claims role that may edit every claim but never
  open or delete one: copy **Claims Adjuster**, untick *Create an event* and
  *Delete an event* under **Events**, and save.
</Tip>

Two roles may share a display name, so give each a distinct name to keep the
role picker unambiguous.

## Edit a role

Opening a role shows its origin and state, a count of the members and API keys
holding it, and three areas: **Details**, the permission checklist, and
**Members**. The **Edit details**, **Delete role**, and **Save** buttons appear
only for roles that can manage roles, and never on Admin.

<Frame caption="The role editor: details on top, then the permission checklist grouped by section, with the Events group expanded.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/role-editor.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=c5687165b9ce4974209a2716afa11cb6" alt="The Event Manager role editor showing a Custom pill, Edit details, Delete role and Save buttons, the Details section with the role name and description, Expand all and Collapse all controls, a One column / Two columns toggle, and the Underwriting & Claims section with Policies, Quotes and an expanded Events group of eight checked permissions." width="1440" height="900" data-path="assets/app/admin/role-editor.png" />
</Frame>

### Details

The **Role name** and **Description** are plain text until you select **Edit
details**, which turns them into fields. Renaming a role doesn't touch its
permissions. While editing details the same button reads **Cancel** and
reverts only the name and description.

### Permissions

Permissions are grouped into five sections — **Underwriting & Claims**,
**Financials**, **Documents**, **Collaboration**, and **Administration** — and
within each section by the kind of record they act on: Policies, Quotes,
Events, Invoices, Files, Members, and so on. Each group's header shows how many
of its permissions the role holds, for example **4 of 9**.

* Tick or untick a permission to change the draft. Every permission has a
  **?** button that explains what it covers.
* **Expand all** / **Collapse all** open or close every group; the
  **One column** / **Two columns** toggle changes the layout. Neither is saved
  with the role.
* Select **Save** to apply your changes — the message *"Role saved"* confirms
  it. Changes you haven't saved are discarded when you leave the page.

Changes apply to everyone holding the role the next time their pages load.

### Restricted fields

If your company's field configuration marks some fields as restricted, an
extra block appears at the bottom of the relevant group under the heading
**Restricted fields — from this company's configuration**. Each restricted
group is a permission like any other, for example *Edit claim dates*, and
the fields it covers are listed beneath it as chips: a closed padlock while
the role lacks the permission, an open one once it's ticked.

A role without a restricted-field permission can still **see** those fields —
it just can't change them. This is how you make a handful of fields
read-only for most of your team while a few people keep editing them.

### Editing a standard role for the first time

The first time you change a standard role that is still **In sync** — a rename
counts — you're asked to confirm:

> *"\<Role> still follows the \<Template> template and receives new
> permissions automatically. Once you edit it, it becomes a customized role:
> new template permissions arrive as a notice for you to accept or dismiss
> instead. You only see this once."*

<Frame caption="The one-time confirmation when you first edit a standard role.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/stop-following-template-dialog.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=7be758ad356ddd58cf0dc8324582d590" alt="The Stop following the template? dialog over the Claims Adjuster editor, explaining that the role still follows its template and will become a customized role, with Edit this role and Cancel buttons." width="1440" height="900" data-path="assets/app/admin/stop-following-template-dialog.png" />
</Frame>

Select **Edit this role** to continue or **Cancel** to discard that change.
Customizing a standard role is safe and common — it is how most companies fit
the standard roles to their own team.

## Keep up with template changes

AI Insurance occasionally adds permissions to the templates, usually because a
new feature shipped with a permission of its own. What happens next depends on
the role's state:

* **In sync** roles receive the new permissions automatically. Nothing to do.
* **Customized** roles don't change on their own. Instead the Roles table
  shows **+N new** beside the role, and opening it shows a notice: *"N new
  permissions available. The \<Template> template gained these since
  \<Role> was last synced,"* followed by the list. Select **Accept all**
  to grant them or **Dismiss** to leave the role as it is. To take only some,
  select **Accept all**, untick the ones you don't want, and **Save**.
* **Custom** roles that were never based on a template get no notices; you
  grant new permissions by hand if you want them.
* **Admin** always holds every permission, including new ones.

<Frame caption="A customized role's notice listing the permissions its template gained, with Dismiss and Accept all.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/template-additions-notice.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=ab4217981da05093b970139f80ddcb9d" alt="The Manager role editor with Template and Customized pills and a banner reading 1 new permission available. The Manager template gained these since Manager was last synced, listing Delete a finished export run, with Dismiss and Accept all actions." width="1440" height="900" data-path="assets/app/admin/template-additions-notice.png" />
</Frame>

Either choice retires the notice. You aren't asked about the same additions
twice.

## Move members between roles

The **Members** section at the bottom of a role lists everyone who holds it,
with their name and email. To move someone onto this role, pick them from the
**Add members** dropdown — each option shows the person and the role they hold
now. The change applies immediately and you'll see *"\<name> now holds
\<Role>"*.

Because every member holds exactly one role, there is no "remove from role"
action: you move a person by assigning them another role, here or from the
[Users tab](/app/admin/users-roles#change-a-users-role). You can't change your
own role from either place.

## Delete a role

Select **Delete role** in the role editor. If nobody holds the role it is
simply removed. If members or API keys hold it, the dialog asks you to pick the
role they **Move them to** — the move and the delete happen together, so no
one is ever left without a role. Deleting a role cannot be undone.

<Frame caption="Deleting a role nobody holds; a held role asks where its members and keys move to.">
  <img src="https://mintcdn.com/ai-insurance-fmv1/Vnm5Wq5W7Ldldz-g/assets/app/admin/delete-role-dialog.png?fit=max&auto=format&n=Vnm5Wq5W7Ldldz-g&q=85&s=10ca73e08701b221686b503c46453ef6" alt="The Delete Event Manager? dialog stating that nobody holds Event Manager, so deleting it affects no one and cannot be undone, with Delete role and Cancel buttons." width="1440" height="900" data-path="assets/app/admin/delete-role-dialog.png" />
</Frame>

The **Admin** role cannot be deleted.

## The Admin role

Admin is your company's locked role:

* It always holds every permission your company can use, including
  permissions added later and any restricted-field permissions from your
  configuration.
* It cannot be edited or deleted. Opening it shows *"Admin always holds every
  permission the company can use, so there is nothing to change here. Build a
  narrower role instead."*
* It is the only role that can create, edit, and delete roles. Of the
  standard roles it is also the only one that can invite users, change their
  roles, and remove them, though a custom role can be given those permissions.
* You can't move the last Admin in your company to another role — assign
  another Admin first. This keeps you from locking everyone out of role and
  user management.

To give someone broad access *without* role management, don't make them an
Admin — copy Admin into a new role and untick **Manage roles** and the
**Members** permissions.

## Roles and API keys

API keys hold roles exactly as users do, and appear in each role's **API keys**
count. A key can be given any of your company's roles, including a custom one
built just for that integration. See [API keys](/app/admin/api-keys#keys-have-roles).
