Skip to main content
Access follows the structure of the organization. The organization holds projects, and each project holds its connector profiles and linked accounts. Start from what the person needs:

Organization Roles

Let someone run the organization, or limit them to the projects they’re added to.

Project Roles

Hand someone a project, let a team connect their own accounts, or give read-only access.

Connector Profile Access

Limit who can link accounts through a sensitive connector profile.

Shared Accounts

Let several people work through one linked account.

Groups

Give the same roles to many people at once, and change them in one place.

Give someone access to a provider

A user can reach a provider by linking their own account through a connector profile, or by using an account someone else has already linked:
Use neither if:
Everyone in the company books meetings from their own calendar.
  1. Leave the calendar connector profile Shared.
  2. Give each person Project Member on the project, as described in Project Roles.
  3. Each person links their own account. Other Project Members can’t use it unless it’s shared with them.
Use Connector Profile Access if:
A sales team of account executives, with two sales managers who also fix records in bulk.
  1. Create two CRM connector profiles: one with admin scopes, and one with read-only scopes.
  2. Restrict the admin-scoped profile, and leave the read-only one Shared.
  3. Grant the sales managers Connector Profile Member on the admin-scoped profile.
  4. Each manager links their own CRM account through the admin-scoped profile.
  5. Everyone else links through the read-only profile.
An HR team that handles payroll.
  1. Restrict the HR connector profile that reaches payroll data.
  2. Grant the HR team’s group Connector Profile Member on it.
  3. Only the HR team can link accounts through it.
Use Shared Accounts if:
A support lead and a team of agents who all answer customers from one shared inbox.
  1. The support lead links the mailbox once.
  2. They grant each agent Account Member on it.
  3. Agents send replies through the mailbox without needing its password.
A team of analysts sharing the company’s single licensed seat on a reporting tool.
  1. The person who links the reporting tool’s single seat becomes its Account Admin.
  2. They grant the analysts Account Member on it.
  3. Everyone runs reports through that one seat.
Use both if:
The head of talent holds the only admin login for the recruiting system. Two recruiters need to use it, without connecting their own.
  1. Restrict the recruiting system’s connector profile to the head of talent, as Connector Profile Member.
  2. The head of talent links the admin login through it.
  3. They grant the two recruiters Account Member on that linked account.

Which role applies

A user’s effective role on a resource is the strongest role they hold there.

Roles from groups

When a user holds one role directly and another through a group, the stronger one applies. For example: To see each member’s effective role on a project, open Project Settings > Access.

Roles inherited by accounts

An account also inherits access from the organization and from its parent project. Users with the following roles can access an account without being in its Members list: A Project Member inherits nothing. They see only the accounts they linked and any they’ve been granted access to.

Explicit account access

By default, Organization Admins and Project Admins are Account Admin on every account they can reach, so they can run actions with anyone’s linked account. Explicit account access removes that. With it enabled, admins can view every account, but need a grant to do more:
Explicit account access isn’t a setting in the dashboard. Contact StackOne to enable it for the organization.