> For the complete documentation index, see [llms.txt](https://docs.itoc360.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.itoc360.com/users-and-access-management/roles-and-permissions.md).

# Roles & Permissions

Every user in your ITOC360 organization has a role, and that role decides what they can see and do from acknowledging an incident to changing the subscription. ITOC360 ships with three built-in roles that cover most teams, and if none of them is quite right, you can build your own role by picking exactly the permissions it should include.

You'll find everything under **Management → Roles & Permissions**.

Creating and managing custom roles is available on the **Advanced** and **Premium** plans. The three built-in roles are available on every plan.

### Built-in roles

**Admin** has every permission. Admins are the only ones who can delete things (sources, teams, schedules, escalation policies, channels, domains, maintenance windows, roles), change the plan or payment method, and assign a role to a user. Keep this role for the small group of people who genuinely need to run the organization.

**Manager** is the day-to-day operator. Managers can create and edit almost everything, acknowledge incidents, silence alerts, and invite new users — but they cannot delete anything, cannot touch billing beyond viewing it, and cannot assign roles to other users. This is the right fit for team leads and senior on-call engineers.

**Viewer** is read-only. Viewers can see alerts, incidents, sources, schedules, teams, escalation policies, channels, domains, maintenance windows, roles, and the billing overview — but they can't change any of it, and they can't acknowledge incidents or silence alerts. Useful for stakeholders who want visibility without the risk of a stray click.

Built-in roles can't be edited or deleted. If you need something between Manager and Viewer, create a custom role instead.

### Permissions reference

The tables below show what each built-in role can do. When you create a custom role, these same permissions are the ones you toggle on and off.

#### Alerts

| Permission     | Admin | Manager | Viewer |
| -------------- | ----- | ------- | ------ |
| View alerts    | ✅     | ✅       | ✅      |
| Silence alerts | ✅     | ✅       | —      |

#### Incidents

| Permission            | Admin | Manager | Viewer |
| --------------------- | ----- | ------- | ------ |
| View incidents        | ✅     | ✅       | ✅      |
| Acknowledge incidents | ✅     | ✅       | —      |

#### Sources

| Permission                              | Admin | Manager | Viewer |
| --------------------------------------- | ----- | ------- | ------ |
| View monitoring sources                 | ✅     | ✅       | ✅      |
| Create new sources                      | ✅     | ✅       | —      |
| Edit source settings and configurations | ✅     | ✅       | —      |
| Remove sources                          | ✅     | —       | —      |

#### Escalations

| Permission                                         | Admin | Manager | Viewer |
| -------------------------------------------------- | ----- | ------- | ------ |
| View escalation policies                           | ✅     | ✅       | ✅      |
| Create new escalation policies                     | ✅     | ✅       | —      |
| Edit escalation policy settings and configurations | ✅     | ✅       | —      |
| Remove escalation policies                         | ✅     | —       | —      |

#### Schedules

| Permission                                | Admin | Manager | Viewer |
| ----------------------------------------- | ----- | ------- | ------ |
| View schedules                            | ✅     | ✅       | ✅      |
| Create new schedules                      | ✅     | ✅       | —      |
| Edit schedule settings and configurations | ✅     | ✅       | —      |
| Remove schedules                          | ✅     | —       | —      |

#### Teams

| Permission                            | Admin | Manager | Viewer |
| ------------------------------------- | ----- | ------- | ------ |
| View teams                            | ✅     | ✅       | ✅      |
| Create new teams                      | ✅     | ✅       | —      |
| Edit team settings and configurations | ✅     | ✅       | —      |
| Remove teams                          | ✅     | —       | —      |

#### Channels

| Permission                               | Admin | Manager | Viewer |
| ---------------------------------------- | ----- | ------- | ------ |
| View notification channels               | ✅     | ✅       | ✅      |
| Create new notification channels         | ✅     | ✅       | —      |
| Edit channel settings and configurations | ✅     | ✅       | —      |
| Remove notification channels             | ✅     | —       | —      |

#### Maintenances

| Permission                                          | Admin | Manager | Viewer |
| --------------------------------------------------- | ----- | ------- | ------ |
| View maintenance windows                            | ✅     | ✅       | ✅      |
| Create new maintenance windows                      | ✅     | ✅       | —      |
| Edit maintenance window settings and configurations | ✅     | ✅       | —      |
| Remove maintenance windows                          | ✅     | —       | —      |

#### Domains

| Permission                              | Admin | Manager | Viewer |
| --------------------------------------- | ----- | ------- | ------ |
| View domains                            | ✅     | ✅       | ✅      |
| Create new domains                      | ✅     | ✅       | —      |
| Edit domain settings and configurations | ✅     | ✅       | —      |
| Remove domains                          | ✅     | —       | —      |

#### Roles

| Permission                                                                       | Admin | Manager | Viewer |
| -------------------------------------------------------------------------------- | ----- | ------- | ------ |
| View roles, their assigned permissions, and the assignable permissions catalogue | ✅     | ✅       | ✅      |
| Create new roles within the tenant                                               | ✅     | ✅       | —      |
| Edit roles and their permission assignments                                      | ✅     | ✅       | —      |
| Remove roles from the tenant                                                     | ✅     | —       | —      |

#### Users and invitations

| Permission                            | Admin | Manager | Viewer |
| ------------------------------------- | ----- | ------- | ------ |
| Invite users to tenants               | ✅     | ✅       | —      |
| Assign a role to a user in own tenant | ✅     | —       | —      |

#### Billing

| Permission                                                             | Admin | Manager | Viewer |
| ---------------------------------------------------------------------- | ----- | ------- | ------ |
| View the subscription, plan usage, and invoices                        | ✅     | ✅       | ✅      |
| Change the plan, seats, or payment method, and cancel the subscription | ✅     | —       | —      |

<figure><img src="https://4108595529-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FimJRSa33y5Ej6rwXrBeA%2Fuploads%2FCiKwOthuusdUW6XLKWEG%2F43_Ekran%20Resmi%202026-09-01%2015.05.39.png?alt=media&amp;token=55c37425-41b8-4cd3-9f18-3f989c84f1b8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4108595529-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FimJRSa33y5Ej6rwXrBeA%2Fuploads%2FZKBbYL6BpHXSv4nBmKhc%2F44_Ekran%20Resmi%202026-09-01%2015.06.13.png?alt=media&amp;token=c91a5d5b-5d7b-4365-9b61-599944b26c14" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4108595529-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FimJRSa33y5Ej6rwXrBeA%2Fuploads%2F4zf8dgckJKj2VaGZkQBt%2F45_Ekran%20Resmi%202026-09-01%2015.06.44.png?alt=media&amp;token=8a1aa569-ce17-4e5e-999d-7d3eb0b19522" alt=""><figcaption></figcaption></figure>

Notice the split in the **Roles** table: a Manager can create and edit roles, but cannot assign a role to a user or delete a role. Those two actions stay with **Admins**.

### Creating a custom role

1. Go to **Management → Roles & Permissions**.
2. Click **Create Role** in the top right.
3. Give the role a name that describes the job, not the person — `Network On-Call`, `Read-only Auditor`, `Billing Owner`.
4. Toggle on the permissions the role should have. Permissions are grouped by area, so start with the group you care about most.
5. Save the role.

The new role appears as a column in the permissions table alongside Admin, Manager, and Viewer, and becomes selectable everywhere a role is chosen.

A few things worth keeping in mind while you pick permissions:

* **Grant the view permission for anything you grant edit on.** A role that can edit schedules but can't view them will hit dead ends in the UI.
* **Delete is always the sharpest edge.** Removing a source, schedule, or escalation policy is not recoverable, so hand out the remove permissions deliberately.
* **Think about who can hand out power.** A role with *Create new roles*, *Edit roles*, and *Assign a role to a user* can effectively promote anyone, including itself.

### Assigning a role to a user

1. Go to **Management → Users**.
2. Find the user and change their role.

Only a role with **Assign a role to a user in own tenant** can do this — by default, Admin.

Role changes take effect on the user's next page load; they don't need to sign out and back in.

### Choosing a role when you invite someone

The invitation form now includes a role selector, so new users land with the right permissions from their very first login instead of being fixed up afterwards.

1. Go to **Organization → Invites** and start a new invitation.
2. Enter the email address.
3. Pick the role from the dropdown — built-in and custom roles both appear here.
4. Send the invitation.

Inviting requires the **Invite users to tenants** permission, which Admin and Manager both have.

<figure><img src="https://4108595529-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FimJRSa33y5Ej6rwXrBeA%2Fuploads%2FQ3O4b8LOEqOp027RuFp6%2F46_Ekran%20Resmi%202026-09-01%2015.21.28.png?alt=media&amp;token=ea090cb9-6dd1-4e02-ae9a-269a9713089f" alt=""><figcaption></figcaption></figure>

### Editing and deleting a role

Open a custom role from **Roles & Permissions** to change its name or adjust its permissions. Changes apply to everyone already holding that role, so a permission you switch off disappears for those users right away.

Deleting a role needs the **Remove roles from the tenant** permission. Built-in roles cannot be deleted.

### Filtering the table

The permissions table can get long — it covers every permission in the product across every role. Use the search box to filter by permission name, and the **View** control to show or hide role columns so you can compare just the two roles you're interested in.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.itoc360.com/users-and-access-management/roles-and-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
