Skip to main content
Organizations running analytics typically have several kinds of stakeholder, each needing a different level of access to dashboards, datasets, and administrative capabilities. Klaritics uses role-based access control (RBAC) with granular data access controls to manage this. Without a structured roles system, organizations run into unauthorized access to sensitive data, accidental modification or deletion of dashboards, difficulty managing access for large teams, and no visibility into who can perform which actions. Roles are managed under Settings → Users & Permissions.

Default system roles

Klaritics includes predefined roles covering common organizational use cases.
Default roles cannot be edited and cannot be deactivated.

Custom roles

Organizations that need roles tailored to internal workflows can create custom roles from a configurable permission catalogue. Custom roles are created at organization level. Every custom role is:
  • Visible across all applications and projects within the organization
  • Reusable across those applications and projects

Create a custom role

1

Define role details

Provide the role’s identifying information.For example: Role Name Marketing Analyst, Description Can build marketing dashboards, Scope Project.
2

Configure permissions

Select permissions from categorized groups. You can enable or disable each permission for the role.
3

Review the role preview

Before saving, review a summary of what the role grants and restricts.
4

Save the role

Once saved, the role becomes available for assignment.

Role actions and status

The roles list includes a status column. A role is either active or deactivated.
Deactivating a role also deactivates every user associated with that role.

Who can assign which roles

Role assignment is governed by hierarchy.

Custom role behavior

A user holding a custom role can assign that same custom role, and can assign other roles created by a user with that custom role. Example User A holds the custom role Marketing Lead. They can assign Marketing Lead, and roles created by User A. They cannot assign Admin unless the hierarchy permits it.

Multiple roles per user

Users may inherit roles from more than one source:
  • Organization role
  • Team membership
  • Individual assignment
Example A user belongs to the Marketing Team and the Leadership Team, inheriting Marketing Analyst and Executive Viewer. Klaritics combines these permissions during access evaluation.

Conflict resolution

When a user inherits multiple roles, permission conflicts can occur. Klaritics always resolves them the same way: the highest level of access among the assigned roles is granted.
There is no alternative resolution mode to configure. The most permissive role always wins.

Removing users

Removal follows the same hierarchy as assignment.
  • Admin can remove Editors and Viewers
  • Editor can remove Viewers
  • Viewer cannot remove anyone

Next steps