Access on the platform is set in Accounts at four levels: your agency, each client company, each website and each team. What someone can do comes from the strongest role they hold. This article explains each level and gives practical recipes.
Agency roles
Agency roles apply to your own agency staff.
Role | What it can do |
|---|---|
Owner | Full control: agency settings and branding, agency members, and oversight of every company under the agency and its websites |
Admin | The same as the owner, on the owner's behalf |
Member | Belongs to the agency and can see it, but does not manage it |
Agency owners and admins can manage every company under the agency, and act as Manager on its websites, without being added to each company. See Managing companies and websites.
Company roles
Company roles apply to one client company. These are the descriptions shown on the company's Members tab:
Role | What it can do |
|---|---|
Owner | Full control. The only role that can delete the company. |
Admin | Manages the company: edit profile, invite and remove members, change roles, custom roles, and memory. Cannot delete the company. |
Member | Standard access to the company and its websites. No management permissions. |
A company Owner or Admin automatically counts as Manager on every website of that company. A Member only reaches the websites where they have a website role.
When you invite people to a company you can choose Admin or Member. To change someone's role later, open their menu on the Members tab and pick a role under Change role.
Website roles
Website roles decide what someone can do with content on one site, from highest to lowest:
Role | What it can do |
|---|---|
Manager | Full control over settings, members, and all content |
Editor | Edit and publish any content |
Author | Create and publish own content |
Reporter | Create content (needs approval) |
AI User | Restricted AI content (needs approval) |
Reporters and AI Users can't publish directly. Their work goes to the reviewers set on the website. See Setting approvers per website.
Team roles
Team roles control the team itself, not the website.
Role | What it can do |
|---|---|
Lead | Full team management |
Admin | Can manage members |
Member | Standard access |
Viewer | Read-only access |
Guest | Limited access |
What a team's members can do on a website comes from the role the team was given on that website. See Creating teams and linking them to websites.
How access combines
Highest role wins. If someone has a direct website role and another role through a team, they get the higher of the two. Example: direct Reporter plus team Editor means Editor.
Company managers are always Manager. A company Owner or Admin, and an agency owner or admin, always has full Manager rights on the company's websites. A custom role never narrows that.
Company visibility. When a website's Visibility is set to Company, every member of the company can open it, as a Reporter unless they have a higher role.
Removing someone from the company also removes their website roles and team places in that company.
Who can edit AI Memory
Company Owners and Admins can always edit the company's AI Memory.
Members see the memory read-only, unless you give them edit rights:
Open the company and go to Members.
Open the member's menu.
Under AI memory, click Can edit memory.
The member then shows a Can edit memory badge. Click the option again to set them back to read-only. People without edit rights see a view-only notice in AI Memory.
Custom roles
A custom role is a named set of permissions for one company, for example "Junior writer". You can assign it when you add someone to a website or give a team access.
Open the company and click Custom Roles.
Click Create Role.
Under Describe the role, let AI propose it, describe the role in plain language, or click one of the examples next to Try:.
Click Suggest with AI. The AI fills in the name, description and permissions, and explains its choice.
Review Role Name, Slug, Description (Optional) and the Permissions, which are grouped per app. Use Select all or Clear to adjust.
Click Create Role.
To use it, switch on Use a custom role instead when you invite someone to a website or grant a team access, and pick the role. The base role still shows as a label, but the custom role defines the actual permissions.
To delete a custom role, click the trash icon on its card. Members who had it fall back to their base role.
Note: If the permission list says "No services connected to this company yet.", the company has no apps enabled. Contact the UP-TO-DATE support team.
How roles shape the AI App
The cards someone sees on the AI App dashboard follow their role on the selected website. Which features each role gets is set up per role by UP-TO-DATE, and a custom role's permission list controls it for that person.
Switching to another website in the AI App can change the cards, because the role can differ per site.
Reporters don't see cards such as Post Planner, Statistics, Search Stats, Social Post, AI Memory and Social Media Connections. In the blog editor their main button reads Submit for approval.
If someone sees "No apps assigned yet", they have no role that grants any app on that website.
See A tour of the AI App dashboard and Troubleshooting: the AI App dashboard.
Practical recipes
Person | Recommended setup |
|---|---|
Your agency's account managers | Agency Admin, so they can manage every client |
Your agency's copywriters | Agency Member, plus a team with Author or Editor on the clients' sites |
Client's main contact who manages their own people | Company Admin |
Client's staff who write drafts for approval | Company Member with Reporter on their website |
Client contact who only reviews and approves | No account needed: add them as a reviewer on the website's Approval tab |
A freelancer on one site | Company Member with a website role on that one site only |