> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/how-to-documentation/managing-roles-groups-and-permissions.md).

# Managing Roles, Groups, and Permissions

***

### Understanding Roles

Every user in Herd has one of three roles. Your role determines your overall level of access.

| Role         | Who It's For                                        | Access Level                                                                                                               |
| ------------ | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| **Admin**    | Organization owners and security leaders            | Full access to everything. Bypasses all permission checks. Can manage users, groups, billing, and integrations.            |
| **Operator** | Team leads, department heads, training coordinators | Web app access with permissions controlled by group membership. Can only do what their group permissions allow.            |
| **Member**   | Everyone else in your organization                  | No web app access. Interacts with Herd only through Slack or Teams — completing trainings, responding to simulations, etc. |

{% hint style="info" %}
The first user to log in to a new Herd workspace automatically becomes an **Admin**. All subsequent users start as **Operators** and are added to your default group.
{% endhint %}

***

### Understanding Groups

Groups are how you organize Operators and assign them permissions. Think of groups like teams — each group has a set of permissions, and every Operator in that group inherits those permissions.

* Each group has a **name**, **description**, and a **set of permissions**
* An Operator can belong to **multiple groups** — their permissions are the combined set from all groups
* New Operators are automatically added to your organization's **default group**
* Groups can pull members from **Okta**, **Azure AD**, **Google Workspace**, or **Slack** to mirror your existing team structure

{% hint style="warning" %}
When your workspace is first created, a **Full Access** default group is set up automatically — meaning every new Operator has full access to everything. We strongly recommend configuring restrictive groups early.
{% endhint %}

***

### Setting Up Groups

#### 1. Plan Your Access Structure

Before creating groups, decide who needs access to what.

{% tabs %}
{% tab title="Small Team" %}
Keep the default **Full Access** group. All Operators can do everything. Admins handle user management and settings.
{% endtab %}

{% tab title="Department-Based" %}

| Group                                                                       | Recommended Template |
| --------------------------------------------------------------------------- | -------------------- |
| **Security Team** — Full phishing, smishing, training, and reporting access | Security Manager     |
| **HR / Training Team** — Training creation and assignment only              | Training Manager     |
| **Compliance Team** — Compliance campaigns and policies                     | Compliance Manager   |
| **Leadership** — Read-only dashboards and reports                           | Viewer               |
| {% endtab %}                                                                |                      |

{% tab title="Least-Privilege" %}
Create a custom group for each role with only the specific permissions they need. Start with the closest template and remove permissions you don't want to grant.
{% endtab %}
{% endtabs %}

#### 2. Create a Group

{% stepper %}
{% step %}

#### Open Group Settings

Go to **Users** in the left sidebar, then switch to the **Groups** view. (The Groups view requires the **Org Permissions** permission — admins always have it.)
{% endstep %}

{% step %}

#### Create the Group

Click **Create Group**, then give it a name and description.
{% endstep %}

{% step %}

#### Choose a Template

Select a **permission template** as a starting point, or build from scratch.
{% endstep %}

{% step %}

#### Adjust Permissions

Add or remove individual permissions as needed for this group.
{% endstep %}

{% step %}

#### Add Members

Add individual users or connect synced identity provider groups.
{% endstep %}
{% endstepper %}

#### 3. Update Your Default Group

If you don't want new users to automatically have full access:

1. Go to **Users → Groups**
2. Edit the default group's permissions (e.g., change it to Viewer-only)
3. Or create a new limited-permission group and set it as the default under **Default Group for New Users** — the gear icon on the [Users page](/herd-security-docs/users/users.md#user-settings-default-group-for-new-users)

***

### Permission Reference

Admins always have all permissions. The tables below apply to **Operators**.

{% tabs %}
{% tab title="Training" %}

| Permission        | What It Allows                                           |
| ----------------- | -------------------------------------------------------- |
| View trainings    | See all trainings in your organization                   |
| Create trainings  | Build new trainings (manual or AI-generated)             |
| Edit trainings    | Modify existing trainings                                |
| Delete trainings  | Remove trainings permanently                             |
| Assign trainings  | Send trainings to employees via Slack or Teams           |
| Approve trainings | Review and approve pending trainings before they go live |
| {% endtab %}      |                                                          |

{% tab title="Tracks" %}

| Permission    | What It Allows                  |
| ------------- | ------------------------------- |
| View tracks   | See all learning tracks         |
| Create tracks | Build new multi-training tracks |
| Edit tracks   | Modify existing tracks          |
| Delete tracks | Remove tracks                   |
| Assign tracks | Assign tracks to employees      |
| {% endtab %}  |                                 |

{% tab title="Phishing" %}

| Permission        | What It Allows                                       |
| ----------------- | ---------------------------------------------------- |
| View phishing     | See phishing campaigns and results                   |
| Manage templates  | Create, edit, and delete phishing email templates    |
| Approve templates | Review and approve phishing templates                |
| Manage campaigns  | Create, launch, pause, and delete phishing campaigns |
| {% endtab %}      |                                                      |

{% tab title="Smishing" %}

| Permission        | What It Allows                                  |
| ----------------- | ----------------------------------------------- |
| View smishing     | See SMS simulation campaigns and results        |
| Manage templates  | Create, edit, and delete SMS templates          |
| Approve templates | Review and approve SMS templates                |
| Manage campaigns  | Create, launch, pause, and delete SMS campaigns |
| {% endtab %}      |                                                 |

{% tab title="WhatsApp" %}

| Permission        | What It Allows                                       |
| ----------------- | ---------------------------------------------------- |
| View WhatsApp     | See WhatsApp simulation campaigns and results        |
| Manage templates  | Create, edit, and delete WhatsApp templates          |
| Approve templates | Review and approve WhatsApp templates                |
| Manage campaigns  | Create, launch, pause, and delete WhatsApp campaigns |
| {% endtab %}      |                                                      |

{% tab title="Compliance & Policy" %}

| Permission        | What It Allows                             |
| ----------------- | ------------------------------------------ |
| View compliance   | See compliance campaigns and status        |
| Manage compliance | Create, edit, and run compliance campaigns |
| View policies     | See all policies                           |
| Manage policies   | Create, edit, delete, and publish policies |
| {% endtab %}      |                                            |

{% tab title="Reporting" %}

| Permission       | What It Allows                                                          |
| ---------------- | ----------------------------------------------------------------------- |
| View dashboard   | Access the Dashboard and Reports hub (`reporting.dashboard`)            |
| View risk scores | See individual employee risk scores (`reporting.risk_scores`)           |
| Configure risk   | Tune risk scoring — the risk-appetite weights (`reporting.risk_config`) |
| {% endtab %}     |                                                                         |

{% tab title="Gamification" %}

| Permission          | What It Allows                                            |
| ------------------- | --------------------------------------------------------- |
| Manage gamification | Configure leaderboards and points (`gamification.manage`) |
| {% endtab %}        |                                                           |

{% tab title="AI Coach" %}

| Permission      | What It Allows                                                                     |
| --------------- | ---------------------------------------------------------------------------------- |
| View AI Coach   | Access the AI Coach section and view conversation scores (`ai_governance.view`)    |
| Manage AI Coach | Configure AI Coach settings, connections, and remediation (`ai_governance.manage`) |

These permissions gate the **AI Coach** section. AI Coach is currently in beta and enabled per organization.
{% endtab %}

{% tab title="GitHub Integration" %}

| Permission                | What It Allows                                                 |
| ------------------------- | -------------------------------------------------------------- |
| View GitHub integration   | View GitHub integration data (`github_integration.view`)       |
| Manage GitHub integration | Configure the GitHub integration (`github_integration.manage`) |

The GitHub integration is in **beta**.
{% endtab %}

{% tab title="Users & Groups" %}

| Permission    | What It Allows                                        |
| ------------- | ----------------------------------------------------- |
| View users    | See the user list and profiles                        |
| Manage users  | Add, edit, and deactivate users                       |
| View groups   | See group configurations                              |
| Manage groups | Create, edit, and delete groups and their permissions |
| {% endtab %}  |                                                       |

{% tab title="Organization" %}

| Permission            | What It Allows                                                                                                                                                                          |
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Organization settings | Modify organization-level settings (name, branding, SMS) — also gates the Settings sidebar entry (`org.settings`)                                                                       |
| Integrations          | Configure Slack, Teams, Okta, Azure AD, SCIM tokens, and other integrations (`org.integrations`)                                                                                        |
| Permissions settings  | Manage groups' permissions and the admin list — an operator holding this can grant any permission, so give it only to groups trusted with permission administration (`org.permissions`) |
| {% endtab %}          |                                                                                                                                                                                         |
| {% endtabs %}         |                                                                                                                                                                                         |

***

### Permission Templates

Templates are pre-built permission sets that make group setup faster. Use them as a starting point — you can add or remove individual permissions after applying one.

| Template               | Best For                       | Includes                                                                                                                 |
| ---------------------- | ------------------------------ | ------------------------------------------------------------------------------------------------------------------------ |
| **Training Manager**   | HR teams, L\&D coordinators    | View, create, edit, delete, and assign trainings                                                                         |
| **Training Reviewer**  | Managers who approve content   | View and approve trainings                                                                                               |
| **Security Manager**   | Security team leads            | Full training, phishing, smishing, tracks, reporting, and gamification access                                            |
| **Compliance Manager** | Compliance officers, GRC teams | Compliance campaigns, policies, and dashboard access                                                                     |
| **Viewer**             | Leadership, auditors           | Read-only access to all content, dashboards, users, and groups (also includes AI Coach view and GitHub integration view) |
| **Full Access**        | Small teams, power users       | All permissions — equivalent to Admin, but still governed by group membership                                            |

{% hint style="info" %}
Three sensitive permissions are excluded from the default **Full Access** grant and must be added deliberately: **Permissions settings** (`org.permissions`, which lets a holder grant any permission), network access controls (`org.network`), and platform administration (`system.admin`). Since every new web user lands in your default group, anything in that group's grant is effectively held by everyone who can sign in.
{% endhint %}

***

### What Happens Without a Permission

Navigation follows your permissions: sidebar entries and in-page links to pages you can't access are hidden or rendered as plain text, and opening such a page directly redirects you to the first page you *can* see. Two useful exceptions:

* **Managers always see their own direct reports' results.** A manager (by the directory `manager` relationship) can view their reports' training and phishing results — on the Dashboard's **Team Report** widget and by asking [HerdAI](/herd-security-docs/herdai/herdai.md) — with no permission grants needed. This never extends to anyone else's team.
* **Members see their own data.** Everyone can ask the Herd bot about their own trainings and phishing results.

***

### Ownership Scoping

When Operators create trainings, campaigns, or other content, that content is owned by their group.

* Operators can only **edit and delete** content owned by groups they belong to
* Operators can **view** content from other groups if they have the relevant view permission
* **Admins** can see and manage all content regardless of ownership

This prevents department heads from accidentally modifying each other's work while still allowing visibility across the organization.

***

### Common Questions

<details>

<summary>Can an Operator give themselves more permissions?</summary>

No. Only users with the **Manage Groups** permission can change group permissions, and they can only modify groups — not grant themselves Admin access. Only an Admin can promote someone to Admin.

</details>

<details>

<summary>What happens when I remove someone from a group?</summary>

They immediately lose that group's permissions. If they belong to other groups, they keep those permissions. If removed from all groups, they have no permissions and will see an empty dashboard.

</details>

<details>

<summary>Can I sync groups with my identity provider?</summary>

Yes. Groups can pull members from **Okta**, **Azure AD**, **Google Workspace**, and **Slack**. When someone is added or removed in your IdP, their Herd permissions update automatically.

</details>

<details>

<summary>What's the difference between an Admin and an Operator with Full Access?</summary>

Functionally very similar, but Admins can: promote or demote other Admins, manage billing, impersonate users for troubleshooting, and their access can never be restricted by group changes. An Operator with Full Access can lose permissions if their group is modified.

</details>

<details>

<summary>How do I restrict the default group?</summary>

Go to **Users → Groups**, edit the default group, and change its permissions to something more restrictive (e.g., Viewer). To change **which** group is the default, use the gear icon on the [Users page](/herd-security-docs/users/users.md#user-settings-default-group-for-new-users). All future new users will receive these limited permissions instead of full access.

</details>

<details>

<summary>I accidentally locked myself out. What do I do?</summary>

Ask another Admin in your organization to restore your group membership. If no other Admins are available, contact Herd support.

</details>

***

### Best Practices

{% hint style="success" %}

1. **Set up groups early** — Don't leave the default Full Access group unchanged. Configure proper groups before inviting your team.
2. **Use least privilege** — Start with the minimum permissions needed and add more as required.
3. **Mirror your org structure** — Use IdP group sync so permissions stay up to date automatically.
4. **Review permissions quarterly** — As roles change, make sure group memberships still reflect current responsibilities.
5. **Keep at least two Admins** — So you're never locked out if one Admin leaves the organization.
6. **Use templates as starting points** — They cover the most common use cases and save setup time.
   {% endhint %}
