Ideal Role Permission Profiles

Use these profile templates as a starting point. Adjust based on business process and product entitlement.

Profile 1: Tenant Administrator

  • Purpose: Full platform ownership and emergency break-glass operations.
  • Core permissions: Tenant Administrator, role management set, organisation settings set, SSO settings set, API token generation, user/profile management set.
  • Caution: Restrict user count and enforce MFA + audit review.

Profile 2: Platform Administrator

  • Purpose: Day-to-day setup administration without full tenant break-glass scope.
  • Core permissions: View/Edit organisation settings, branding/privacy, custom domain, SSO provider management, API token view/generate (if integration owner), user/profile/role administration.
  • Avoid by default: Log In As User unless support team needs it.

Profile 3: Revenue Operations / CRM Admin

  • Purpose: Deal room setup, CRM connection setup, stage mapping, login fields, email template operations.
  • Core permissions: View/Edit Deal Room Setup set, Manage Service CRM Connection, email template create/edit/activate, Request Content governance.
  • Optional: Report Type management and Search Index diagnostics/reindex.

Profile 4: Sales Manager

  • Purpose: Team-level visibility and analytics consumption.
  • Core permissions: View All Deal Room, View All Content, View Threads/View All Threads, View Reports, View Storage/AI/Audit analytics.
  • Optional: Create/Edit Reports for manager-owned dashboards.

Profile 5: Seller / Account Executive

  • Purpose: Execute deal-room workflow and content delivery.
  • Core permissions: View/Create/Edit Deal Room, View/Create/Edit content, download content, mailbox usage, connections, playbook access.
  • Avoid by default: All “View All” permissions and setup/admin permissions.

Profile 6: Content Manager

  • Purpose: Maintain content library quality and lifecycle.
  • Core permissions: View/Create/Edit/Delete Content, View Recycle Bin, Restore Content, Download Content, Manage Content Archive Users.
  • Optional: View analytics and report creation for content performance reporting.

Profile 7: Reporting Analyst

  • Purpose: Build analytics assets for business teams.
  • Core permissions: View Reports, Create Reports, Edit Reports, Export Reports.
  • Optional: Delete Reports (only for report admins), View Report Types metadata/types.

Profile 8: CPQ Specialist

  • Purpose: Manage pricing, proposals, and approval flows.
  • Core permissions: Company, Proposals, Pricebooks, Offerings, Approval Processes, and Order Templates (View/Create/Edit as required).
  • Optional: corresponding Activate/Deactivate and Delete permissions only for owner roles.

Training Admin

  • Purpose: Training lifecycle management and certification governance.
  • Core permissions: View/Create/Edit/Activate-Deactivate Training, Assign Training, Certify Training Reps, View Training Analytics.