Organization Roles
Let someone run the organization, or limit them to the projects they’re added to.
Project Roles
Hand someone a project, let a team connect their own accounts, or give read-only access.
Connector Profile Access
Limit who can link accounts through a sensitive connector profile.
Shared Accounts
Let several people work through one linked account.
Groups
Give the same roles to many people at once, and change them in one place.
Give someone access to a provider
A user can reach a provider by linking their own account through a connector profile, or by using an account someone else has already linked:Example Scenarios
Example Scenarios
Use neither if:
Use Connector Profile Access if:
Use Shared Accounts if:
Use both if:
Everyone should connect their own calendar
Everyone should connect their own calendar
Everyone in the company books meetings from their own calendar.
- Leave the calendar connector profile Shared.
- Give each person Project Member on the project, as described in Project Roles.
- Each person links their own account. Other Project Members can’t use it unless it’s shared with them.
Only sales managers should get admin access to the CRM
Only sales managers should get admin access to the CRM
A sales team of account executives, with two sales managers who also fix records in bulk.
- Create two CRM connector profiles: one with admin scopes, and one with read-only scopes.
- Restrict the admin-scoped profile, and leave the read-only one Shared.
- Grant the sales managers Connector Profile Member on the admin-scoped profile.
- Each manager links their own CRM account through the admin-scoped profile.
- Everyone else links through the read-only profile.
Only the HR team should connect to the payroll system
Only the HR team should connect to the payroll system
An HR team that handles payroll.
- Restrict the HR connector profile that reaches payroll data.
- Grant the HR team’s group Connector Profile Member on it.
- Only the HR team can link accounts through it.
One licensed login for a team
One licensed login for a team
A team of analysts sharing the company’s single licensed seat on a reporting tool.
- The person who links the reporting tool’s single seat becomes its Account Admin.
- They grant the analysts Account Member on it.
- Everyone runs reports through that one seat.
Recruiters need to use the head of talent's recruiting login
Recruiters need to use the head of talent's recruiting login
The head of talent holds the only admin login for the recruiting system. Two recruiters need to use it, without connecting their own.
- Restrict the recruiting system’s connector profile to the head of talent, as Connector Profile Member.
- The head of talent links the admin login through it.
- They grant the two recruiters Account Member on that linked account.
Which role applies
A user’s effective role on a resource is the strongest role they hold there.Roles from groups
When a user holds one role directly and another through a group, the stronger one applies. For example:
To see each member’s effective role on a project, open Project Settings > Access.
Roles inherited by accounts
An account also inherits access from the organization and from its parent project. Users with the following roles can access an account without being in its Members list:
A Project Member inherits nothing. They see only the accounts they linked and any they’ve been granted access to.
Explicit account access
By default, Organization Admins and Project Admins are Account Admin on every account they can reach, so they can run actions with anyone’s linked account. Explicit account access removes that. With it enabled, admins can view every account, but need a grant to do more:Explicit account access isn’t a setting in the dashboard. Contact StackOne to enable it for the organization.