> For the complete documentation index, see [llms.txt](https://kb.bravegen.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kb.bravegen.com/carbon/configuration/user-management/user-roles.md).

# User Roles

Roles & Permissions within the Carbon System

Roles are assigned per user account, and apply within the organisation. Access to specific products may still depend on the subscriptions enabled for that organisation’s account and the items or areas a user has been granted access to.

## Role summaries

The platform defines four core roles: **Administrator**, **Editor**, **Contributor**, and **Reviewer**. Each role inherits a different level of control over subscribed products, operational features, and administration functions. A supplemental fifth role of **External** denotes a contact without access to the system.

* **Administrator**: Full access to all subscribed products, product settings, adding new subscriptions and full user management, including creation of other administrators.
* **Editor**: Full access where granted, except for subscription and user management.
* **Contributor**: Can only see and upload data to tasks where they're the assigned Data Supplier - cannot edit Processes, Entities, Sources, or Inventory Items.
* **Reviewer**: Can only read and export data from areas they have access to. Can leave comments.
* **External:** Cannot access the system. This role can not be manually assigned.

### Collection Roles

A user can be assigned to the following collection roles for a [process](/carbon/core-concepts/data-collection/processes.md) and any tasks it creates.

* **Process Owner** - notified of any issues coming from tasks related to the process *<mark style="color:$warning;">cant be a contributor or reviewer</mark>*
* **Data Approver** - notified when data is quarantined or in task review *<mark style="color:$warning;">cant be a contributor or reviewer</mark>*
* **Data Supplier** - An email address that is notified when task is due, and if any values are disputed. Not necessarily a user account.

### Entity Access Permissions

Non-administrator accounts need to be granted access to reporting entities within the organisation. Access cascades to all child entities within a granted entity. If a new entity is created outside of the user's current access scope they will need to be manually granted access permission. This can be administrated by clicking the 'configure access' button when editing a user's permissions.

## Access matrix

The table below translates the role definitions into feature-level access categories.

| System feature                                        | **Administrator**                        | **Editor**                                                                                            | **Contributor**                                                                           | **Reviewer**                                                                                          |
| ----------------------------------------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| View entity emissions dashboards                      | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Granted Entities</mark>                                                 | <mark style="color:$warning;">Granted Entities</mark>                                     | <mark style="color:$warning;">Granted Entities</mark>                                                 |
| View processes                                        | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only Assigned, unless 'all tasks and processes' enabled</mark>          | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$warning;">If access to 'collect' is given</mark>                                  |
| Create processes                                      | <mark style="color:$success;">Yes</mark> | <mark style="color:$success;">Yes</mark>                                                              | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Edit processes                                        | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only Assigned, unless 'all tasks and processes' enabled</mark>          | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Access Tasks                                          | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only Assigned, unless 'all tasks and processes' enabled</mark>          | <mark style="color:$warning;">Only if assigned as a 'data supplier' on the process</mark> | <mark style="color:$warning;">If access to 'collect' is given</mark>                                  |
| Download Attachments from Tasks                       | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only tasks they can access</mark>                                       | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$warning;">If access to 'collect' is given</mark>                                  |
| Upload data to a task                                 | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only tasks they can access</mark>                                       | <mark style="color:$warning;">Assigned Tasks</mark>                                       | <mark style="color:$danger;">No</mark>                                                                |
| Create new entities in task review                    | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only within granted entities</mark>                                     | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Create new sources in task review                     | <mark style="color:$success;">Yes</mark> | <mark style="color:$success;">Yes</mark>                                                              | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Create new Inventory Items in task review             | <mark style="color:$success;">Yes</mark> | <mark style="color:$success;">Yes</mark>                                                              | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Approve Tasks                                         | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only tasks they can access</mark>                                       | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Add Manual Data to a source                           | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only within Granted Entities</mark>                                     | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Run reports                                           | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only within Granted Entities</mark>                                     | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$success;">Yes</mark>                                                              |
| Export data                                           | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only within Granted Entities</mark>                                     | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$success;">Yes</mark>                                                              |
| Create & Update Inventory Rules                       | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">No, Only you have access to all entities</mark>                         | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Create & Update Inventory Templates                   | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">No, Only you have access to all entities</mark>                         | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| <p>Manage users<br>& create administrators</p>        | <mark style="color:$success;">Yes</mark> | <mark style="color:$danger;">No</mark>                                                                | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Manage payment and subscriptions                      | <mark style="color:$success;">Yes</mark> | <mark style="color:$danger;">No</mark>                                                                | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Leave Comments and upload attachments to activity log | <mark style="color:$success;">Yes</mark> | <mark style="color:$success;">Yes</mark>                                                              | <mark style="color:$success;">Yes</mark>                                                  | <mark style="color:$success;">Yes</mark>                                                              |
| Access Settings                                       | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only if you can access all entities</mark>                              | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Suppliers                                             | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only for entities you have access to</mark>                             | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$warning;">Only for entities you have access to</mark>                             |
| Audit Trail Snapshots                                 | <mark style="color:$success;">Yes</mark> | <mark style="color:$warning;">Only snapshots where you have access to the snapshot root entity</mark> | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$warning;">Only snapshots where you have access to the snapshot root entity</mark> |
| Update Organisation Settings                          | <mark style="color:$success;">Yes</mark> | <mark style="color:$danger;">No</mark>                                                                | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Update Units of Measure                               | <mark style="color:$success;">Yes</mark> | <mark style="color:$success;">Yes</mark>                                                              | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |
| Enable AI Functionality                               | <mark style="color:$success;">Yes</mark> | <mark style="color:$danger;">No</mark>                                                                | <mark style="color:$danger;">No</mark>                                                    | <mark style="color:$danger;">No</mark>                                                                |

## Quick role selection guide

| Use this role when the user needs to...                             | Recommended role |
| ------------------------------------------------------------------- | ---------------- |
| Manage users, subscriptions, and all platform access and settings   | Administrator    |
| Fully operate assigned areas of product.                            | Editor           |
| Submit data to assigned items but not create, delete, or administer | Contributor      |
| Review data, run reports, and export information without editing    | Reviewer         |

## FAQs

<details>

<summary><strong>If an Editor is disabled what happens to processes they are assigned to?</strong></summary>

The user is still assigned to the process, however they are unable to login and access the process. An admin should assign this to another editor or admin

</details>

<details>

<summary><strong>If an Editor is assigned as a process owner, and their role is downgraded to a Contributor or Reviewer, can they still manage the process?</strong></summary>

No - they will still be assigned, but will only have a read only access. An adminstrator should assign&#x20;

</details>

<details>

<summary><strong>Can an Editor manage users?</strong></summary>

No. User management is reserved for Administrators.

</details>

<details>

<summary><strong>Can a Contributor create new records?</strong></summary>

No. Contributors can edit items they have been granted access to, but they cannot create or delete items.

</details>

<details>

<summary><strong>Can a Reviewer export data?</strong></summary>

Yes. Reviewers can access granted areas, including exporting data and reports.

</details>

<details>

<summary><strong>Can a Reviewer approve a task?</strong></summary>

No reviewers are unable to move data through any workflows in the system

</details>
