Roles & Permissions
What this page covers
statycs has five built-in roles. The user who creates the organization is its Super Admin (owner); on top of the role, Admins can scope any non-admin user to a subset of companies and — with the Departments add-on — to a subset of departments. This page is the truth table for the role + scope combination.
TL;DR
Admin sees and edits everything. Editor edits but doesn’t administer. Viewer reads. Guest sees only the published Dashboard. Scoped users (companies / departments) see only what their scope allows.
The five roles
| Role | Sees | Edits | Administers | Seat |
|---|---|---|---|---|
| Super Admin | Everything in the org | Everything | Yes — plus delete org and reassign ownership | Yes |
| Admin | Everything in the org | Everything | Yes (org settings, users, billing) | Yes |
| Editor | Dashboard, Financials, Analysis, Planning | Data uploads, mappings, financials, analysis, plans, drivers | No | Yes |
| Viewer | Dashboard, Financials, Analysis (read-only); plan selection in those sections | Nothing | No | Yes |
| Guest | Published Dashboard only | Nothing | No | No |
The user who creates an organization becomes its Super Admin (the org owner). Super Admin has all the permissions of Admin plus the ability to delete the organization and reassign ownership. Every other role is assigned by an Admin afterwards.
What admins administer
- Settings → Organization — org name, logo, defaults for new companies.
- Settings → Users — invite, edit, remove users; assign role, company scope, department scope.
- Settings → Billing — subscription, cycle, add-ons, payment, invoices.
- Data → Organizational data — Financial Statement Design, Departments matrix, FX rates.
- Activate plans — promote a draft plan to active. Editors can draft; only admins can activate.
- Move active plan back to draft — only admins.
- Publish Dashboard commentary — Super Admin and Admin; Editors can draft.
Company scope
Every non-admin user has a Companies scope chip on the Users tab. The chip reads:
- All companies — full access to every company in the org (default).
- Acme GmbH — single company.
- N of M — multiple companies out of the total.
Non-admin users must keep at least one company assigned. Admins are locked to All companies and the chip shows a 🔒 glyph.
A scoped user only sees their assigned companies in the topbar company selector and in every list of companies across the app.
Department scope (Departments add-on)
With the Departments add-on on, every non-admin user gets a second chip — Departments — that scopes them to a subset of org departments. Same chip shape: All / single name / N of M. Empty selection means full access. Admins are locked.
A user with a non-empty department scope is a dept-restricted user. The shell changes for them:
- Sidebar shows only Financials, Planning, and Settings.
- Settings is restricted to the Profile tab — no Organization, Users, or Billing.
- Financials shows only the P&L — Balance Sheet and Cash Flow tabs are hidden.
- The Company / department scope pill is locked to the user’s assigned departments and renders with an amber lock icon. The user cannot widen the scope.
- The Dashboard, Analysis, and Data sections are hidden entirely.
This is the deepest restriction in statycs; use it for departmental contributors who only need to enter their own slice.
Guest access
Guests see the published Dashboard of a company they were invited to — and nothing else. They never consume a paid seat, never see Financials / Analysis / Planning / Data / Settings, and cannot draft commentary.
Guests are useful for board members, advisors, and external readers who need the curated view without exposing the underlying data.
How role + scope interact
Permissions are the intersection of the role and the scope:
- An Editor scoped to Acme GmbH only can edit Acme — not the other companies.
- A Viewer scoped to two departments sees only those two departments’ P&L, read-only.
- An Admin is unscoped by default; the chips on admin rows are locked.
If a user can’t see something they expected, the answer is almost always: their role allows it, but their scope hides it.
Related
- Settings → Users — where roles and scopes are assigned
- Settings overview — short permissions matrix
- Departments — adds the per-user department scope chip
- Sign in & onboarding — what an invited user sees on first sign-in