FlowQi Help Center FlowQi Help Center
Changelog Open app

Roles & Permissions

What are roles and permissions?

In FlowQi, every user has a role. That role is a bundle of permissions — the individual actions someone is allowed to perform, like creating a contact, viewing a project, or managing billing. Instead of setting access per person, you assign a role, and the role decides what they can and can’t do.

You might ask about access rights, authorizations, or who is allowed to do what — in FlowQi that is roles and permissions.

Where to find Roles & Permissions

Open the Admin Console from your avatar menu (click your profile picture in the top-right corner, then Admin Console) and go to Permissions in its sidebar. The page is titled Permissions and shows you all the roles in your account together with the access each one has.

The roles overview

On the left you’ll see the Default account roles list. Click a role to load its permissions on the right. FlowQi ships with these default roles:

RoleTypical use
Super AdminOwner-level access across the account
Team AdminManages a team and the data within it
UserA regular member working on their own data
Guest UserLimited, external-style access

There is also a System Admin role used internally by FlowQi. It is not shown in your account’s roles list and is reserved.

Select any role to open its permission matrix — the full set of permissions, with a checkbox per permission showing whether that role has it. Super Admin effectively has full access across the account.

How permissions are organized

When you select a role, its permissions appear on the right, grouped in three levels:

  1. Module — the product area, such as CRM, Project Management, Time and Resource, Financial Management, Console, or User Profile.
  2. Category — a group within the module, such as contacts, organizations, projects, or tasks.
  3. Permission — a single action with a plain description, for example Create contacts or View all contacts.

Each permission shows as a checkbox with its description. A checked box means the role has that permission.

On this page the permission matrix is read-only — it shows you exactly what each role can do. Permissions are assigned to roles by FlowQi’s defaults; this overview is your reference for who has access to what.

Permissions in the Console area

Within a module, permissions are grouped by the thing they control. As an example, the Console module groups its permissions like this:

GroupExample permissions
SettingsView tenant settings, Update tenant settings
DashboardView console dashboard
PermissionsView all available permissions, Assign permissions to users/roles
RolesView all roles, Assign roles to users
ModulesView all available modules, Assign modules to users/teams
UsersView all users in tenant, Update any user, Delete any user, Invite new users to tenant
TeamsView all teams in tenant, Create new teams, Update any team, Delete any team, View team members, Add members to teams

This list is representative, not exhaustive — other modules (CRM, Project Management, and so on) follow the same pattern with their own groups and permissions.

Permission scopes: all, team, or own

Many permissions come in three scopes, so the same action can be limited to a different set of records:

ScopeMeaning
AllThe action applies to every record in the account (e.g. View all contacts)
TeamThe action is limited to records belonging to the user’s team (e.g. View team contacts)
OwnThe action is limited to records the user owns (e.g. View own contacts)

For most data types there are separate create, view, update, and delete permissions, each available at the all, team, or own level.

What the default roles can do

The defaults follow this pattern across modules:

  • Super Admin — full all-scope access: create, view, update, and delete across the account.
  • Team Adminteam-scope access: works with the data of their own team.
  • Userown-scope access: works with the data they own.
  • Guest User — the most limited access.

So for example, with contacts: a Super Admin can view and edit every contact, a Team Admin sees the team’s contacts, and a User sees only their own.

How a role is assigned to a user

A user gets a role when they’re added to your account, and you can change it later:

  1. When inviting — on the Users page, click Create New User. Besides first name, last name, and email, you pick a Role (and optionally a Team ), then click Invite New User.
  2. Later — open a user from the Users list and change their Role under their settings.

Each user has one role per account, and that role determines everything they can access.

What happens when you lack a permission

Permissions are enforced everywhere in FlowQi. If your role doesn’t include a permission:

  • The matching button or menu item may be hidden (for example + New contact if you can’t create contacts).
  • An action you try to perform is blocked, and you may land on a no permission page.

If you’re missing access you expect to have, ask your administrator to check your role.

Not sure why someone can or can’t do something? Open Admin Console → Permissions, select their role, and read the permission descriptions for the module in question.