---
url: https://docs.seen.io/platform/settings/users-and-roles.md
description: >-
  Explains the user roles in a Seen Workspace, what each role can view and edit,
  and how users are added, changed and removed.
---

# Users and Roles

Every user in the Seen Platform has one or more roles. A role applies to one Workspace, so a user can hold a different role in each Workspace they work in.

## How users are managed

Seen creates users and assigns their roles. To add a user, change a role or remove access, ask your designated administrator to send the request to Seen. Every account is created from a written request, so you always control who has access.

Users log in with a magic link, or with a password and optional two-factor authentication. See [Log in](/platform/login).

## Roles

| Role | Who it is for |
|---|---|
| **Workspace Admin** | Full access to the Workspace, plus control over which AI generation models the Workspace has opted in to. |
| **Workspace Editor** | Full read and write access to the Workspace. |
| **Workspace Viewer** | Read-only access to the Workspace. |
| **Workspace Data** | Teams that manage recipient data, integrations and reporting, without access to Studio. |
| **Agency** | Agencies and creative teams that build videos in Studio, without access to recipient data or reporting. |

## What each permission covers

Each role is built from the permissions below. Edit always includes View.

| Area | View | Edit |
|---|---|---|
| Studio | See templates, Blocks, assets, Brand Kit palettes and the music library | Create and change templates, Blocks, assets and palettes, add music, and generate images and video clips |
| Video designs | See videos and their previews | Create and edit videos, generate previews and publish |
| Projects | See the list of Projects | Create, duplicate, and delete Projects, including from a template |
| Project runs | See how a Project is set up to run | Create, change, activate and delete runs, and test the delivery webhook |
| Recipient data | See and export recipient data, uploads and segments | Upload, process and delete recipient data, manage segments and retry failed videos |
| Dashboard and Insights | See performance metrics | Nothing to edit |
| Activity | See the Activity log | Nothing to edit |
| Properties | See the Workspace's Properties | Create, change and delete Properties |
| API tokens | See API tokens | Create and revoke API tokens |
| OAuth2 clients | See OAuth2 clients | Create and revoke OAuth2 clients |
| External Events | See the webhook configuration | Create, change and delete the webhook |
| AI voices | See available voices | Clone, design, edit and delete voices, generate voice previews and translate subtitles |
| AI model opt-in | | Choose which AI generation models the Workspace has opted in to |
| Custom domains | See custom domains and certificates | Add and remove custom domains and certificates |
| Email notifications | See who is subscribed | Subscribe and unsubscribe |

## What each role can do

| Area | Admin | Editor | Viewer | Data | Agency |
|---|---|---|---|---|---|
| Studio | Edit | Edit | View | No access | Edit |
| Video designs | Edit | Edit | View | No access | Edit |
| Projects | Edit | Edit | View | View | Edit |
| Project runs | Edit | Edit | View | Edit | No access |
| Recipient data | Edit | Edit | View | Edit | No access |
| Dashboard and Insights | View | View | View | View | No access |
| Activity | View | View | View | View | No access |
| Properties | Edit | Edit | View | Edit | No access |
| API tokens | Edit | Edit | View | Edit | No access |
| OAuth2 clients | Edit | Edit | View | No access | No access |
| External Events | Edit | Edit | View | Edit | No access |
| AI voices | Edit | Edit | View | No access | Edit |
| AI model opt-in | Edit | No access | No access | No access | No access |
| Custom domains | Edit | Edit | View | No access | No access |
| Email notifications | Edit | Edit | Edit | Edit | No access |

The Agency role has no access to recipient data, Project runs or reporting. An agency can build and edit videos without seeing who receives them.

## What only Seen can do

Some actions are not part of any role. Seen carries them out on your request:

* Creating Workspaces
* Adding, changing and removing users and their roles
* Scrubbing all recipient data in a Workspace, for example at the end of an agreement

## Seen personnel

Seen staff with administrative access to the Seen Platform can access Workspaces to provide support and operate the Platform. This access is restricted to authorised personnel.
