The roles
What each role may do
What the areas cover:
- Business unit content — everything inside a unit’s events: ticket types, add-ons, bundles, offers, forms, perks, attendees and registrations, agenda, speakers, venues, emails, cohorts, automations, exhibition, housing, check-in, surveys, reports. Update is what running the day needs — checking people in, editing an attendee — which is why On-site staff hold it without Create or Delete.
- Business unit settings — the unit’s name, description, timezone, currency, and access mode, and connecting its payments.
- Teams (business units) — creating, renaming, and removing Business Units themselves.
- Audit log — the organization-wide trail. The event-level and unit-level views of the same trail come with reading content.
- Finance — issuing refunds from an order’s detail page. Moving money is never part of content editing.
- API keys and Webhooks — a key delegates the whole Business Unit to a program; an endpoint sends its entire event stream to another server. Both sit with Finance.
- Data & privacy — data-subject export and erasure. See Data & privacy.
Rules to know
- Roles are fixed. There is no custom role and no per-role editing. The console assigns roles; it does not define them.
- Owner and Admin differ in one thing: only an Owner can delete the organization.
- Governance is Owner/Admin only — audit log, finance, API keys, webhooks, data & privacy. Widening a Planner’s reach into any of these is not possible.
- Organization Owners and Admins always resolve with full access inside every Business Unit. A restricted unit drops the organization-role fallback for everyone else.
- Everyone who arrives through a shared credential starts as Viewer — single sign-on and the organization ID alike. A credential proves which company someone belongs to, not how much authority they hold.
Related
Members & roles
Assigning a role, and overriding it inside one Business Unit.
Business Units
Access modes, and what restricted mode changes.