Organizations & Brands
Organizations & Brands

Roles and permissions

Magister has two layers of roles: at the organization level and at the brand level. Organization roles apply to everything the organization owns; brand roles only apply inside one brand.

Organization roles

Organization Owner — has every permission, including the one thing admins can't do: delete the organization. Every organization has exactly one owner by default (the person who created it).

Organization Admin — can manage organization settings and billing, create brands, invite members, manage integrations and settings for any brand, and view hosted chats across brands. Deleting the organization or permanently deleting a brand is owner-only.

Member — can use brands they've been added to. Cannot manage billing, invite members, or change organization settings.

Brand roles

Brand Admin — can manage the brand's settings, allowed-integration policy, permission policy, and members. Paid-spend and destructive action approvals require this level or an organization manager. Organization owners and organization admins automatically have equivalent access inside every brand.

Brand Member — can use the brand's plan-appropriate features and the connection cards allowed by brand policy. Cannot change brand settings, allowed integrations, or the ask-before policy.

Rule of thumb — if it touches billing or organization membership, you need to be an organization owner or admin. If it changes a brand policy, you need to be a brand admin or organization manager. Ordinary plan, analytics, asset, and execution work only needs access to that brand.