Users, Roles & Permissions
Inviting a user
Organization administrators can invite users at any time after onboarding. Go to
Organization → Users from the platform dashboard.
Select Invite User at the top right of the users grid, enter the person's email address,
and choose the role or roles to assign. Send the invitation and they'll receive an email
with a link to set a password and join the organization.
Invited users appear in the list immediately and become active once they accept.
Roles
A role is a bundle of permissions, and every user needs at least one. Access is not a single
admin switch — these are the roles available to your organization:
| Role | Intended for |
|---|---|
| Client Admin | Organization administrators. Full access, including user and organization management. |
| Client User | Day-to-day builders. Create and run integrations, mappings, apps and related resources. |
| Client View Only | Auditors, stakeholders and observers. Read access, with no ability to create, edit or run. |
| Client Security Resource | Security and compliance staff needing visibility into logs and configuration without build access. |
| Client SFTP Viewer | Sees SFTP configuration only. |
| Client SFTP Manager | Manages SFTP users and settings. |
Additional roles exist for Intely staff — used when our implementation or support teams work
inside your organization — and are not assignable by you.
The exact permissions attached to each role are shown on the role itself in
Organization → Users. Treat that screen as authoritative, since roles are occasionally
extended as new modules ship.
Log visibility is granted per log type — see Log Center.
How permissions are organized
Roles are assembled from granular permissions grouped by module. Knowing the shape helps when
you need to explain why someone can see something but not change it:
| Module | Available permissions |
|---|---|
| Integrations | Create · Edit · Delete · View · Run |
| Mappings | Create · Edit · Delete · View · Run |
| Data Types | Create · Edit · Delete · View |
| Crosswalks | Create · Edit · Delete · View · Run |
| Comparisons | Create · Edit · Delete · View · Run |
| My Apps | Create · Edit · Delete · View |
| App Instances | Create · Edit · Delete · View |
| Data Processor | Create Job · Edit Job · Delete Job · View Job · Run Job |
| Agents | Create · Edit · Delete · View |
| Intely File System | View · Edit · Request Access |
| VPN Management | Create · Edit · Delete · View |
| SFTP | View · Edit |
| Logging | Platform · App Request · Comparison · Mappings · Integration · SFTP · Script · Data Processor |
| User Management | Create · Edit · Delete · View · Reset own password · Reset another user's password |
| Organization Management | Edit · View |
| Notifications | View · Edit |
Two things are worth noticing.
Run is separate from Edit throughout. This is how you satisfy the common requirement:
let the on-call team re-run a failed integration, but don't let them change it.
Logging permissions are per log type. You can grant visibility into integration logs
without exposing SFTP or platform logs.
Editing an existing user
Select the user from Organization → Users, update their details or roles, and save.
Password resets
- Users reset their own password from Account → My Profile, subject to the
reset own password permission. - Administrators holding reset another user's password can trigger a reset from the
user's row.
SFTP users
SFTP users are a distinct user type with their own management surface, separate from platform
users. See SFTP.
Sub-organization users
If your organization has child organizations, users can be synced down from the parent rather
than created separately in each one. See Sub-Organizations.
Updated 14 days ago
