- Administration
- Settings
- Role Permissions
Role Permissions
Overview
The Role Permissions page (Settings > Permissions) lets you control which permissions each role — like Manager or Team Member — has across your whole organisation. Turning a permission on or off here applies to every user with that role, so you can tailor what a role can do without editing each user one by one.
Who Can Manage Role Permissions
Only users who can view and update settings — typically Admin and Account Owner users — can open Settings > Permissions and edit these overrides. Other roles won't see the page.
Editing Role Permissions
- Go to Settings > Permissions.
- On the Role Permissions card, click Edit.
- Tick or untick the permissions you want to enable or disable for each role.
- Save your changes. The new permissions apply to all users with that role straight away.

Available Role Permissions
The permissions you can configure depend on the role. The tables below show each configurable permission and whether it is enabled by default.
Manager
| Permission | Default |
|---|---|
| Can create document categories | On |
| Can update document categories | Off |
| Can create participant tags | On |
| Can update participant tags | On |
| Can view participant invoices without finance module access | Off |
Team Member
| Permission | Default |
|---|---|
| Can view all contacts | On |
| Can view all organisations | On |
| Can create participant plan services | On |
| Can delete participant plan services | On |
| Can create document categories | On |
| Can update document categories | Off |
| Can create participant tags | On |
| Can update participant tags | On |
| Can view participant invoices | Off |
| Can view other team members' calendars | Off |
| Can view all notes and tasks | On |
| Can view notes and tasks for users in their user group | On |
Notes & Tasks Visibility for Team Members
Two of the Team Member permissions work together to control which notes and tasks a Team Member can see. Because the limited option is based on shared User Groups, it helps to know which groups count.
Which User Groups Count
Astalty has three kinds of User Groups (see the User Groups guide for how to create and manage them):
- Role-based groups — Admin, Manager and Team Member. Every user is automatically added to the group matching their role, and it updates whenever their role changes. These are ignored for notes and task visibility — sharing the Team Member group with someone doesn't let you see their notes.
- Team groups — if you use Teams, Astalty creates a reserved group for each team and adds members automatically. A user can belong to only one team. These count.
- Custom groups — groups you create yourself (for example, "Support Coordinators" or "Finance"). These count.
So for visibility, what matters is whether two people share at least one Team or Custom User Group. Role-based groups are excluded.
How the Two Settings Work Together
Both settings live on a Team Member's permissions, and "Can view all notes and tasks" always takes precedence over the more limited user-group option:
- Can view all notes and tasks — On (default): the Team Member sees every note and task across the organisation. The user-group permission is ignored while this is on.
- Can view all notes and tasks — Off, Can view notes and tasks for users in their user group — On: the Team Member sees notes and tasks they created, plus those created by anyone who shares a Team or Custom User Group with them.
- Both Off: the Team Member sees only the notes and tasks they created themselves.
A Quick Example
Alice is in the Support Coordination custom group. Bob is in Support Coordination and Finance. Charlie is only in Finance.
With "Can view all notes and tasks" off and the user-group setting on, Alice sees her own notes and tasks plus Bob's — they share Support Coordination. She can't see Charlie's, because they have no Team or Custom User Group in common.
Related Role-Wide Settings
Chat messaging between roles — which roles a Manager, Team Member, or Support Worker can start conversations with — is also configured role-wide, but under Settings > Chat rather than on this page.