> For the complete documentation index, see [llms.txt](https://codifi-fdm.gitbook.io/codifi-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://codifi-fdm.gitbook.io/codifi-docs/cross-platform-features/roles-based-access-controls-rbac.md).

# Roles-Based Access Controls (RBAC)

How Codifi controls who can see and do what — across tenants, Projects, and the Library.

Codifi uses **role-based access control (RBAC)** to decide what each user can see, edit, and manage. Every user in your tenant has one or more roles, and those roles determine which features and Projects are available to them.

This page covers the role model at a high level and points to the built-in **Roles & Permissions** reference inside the web app for the exact feature-level breakdown.

***

## The Two Levels of Access

Access in Codifi works at two levels — they layer on top of each other.

### 1. Tenant-Level Role

Your **Tenant role** controls what features you can use anywhere in the tenant: settings, the Library, user management, analytics, and so on. Most users have one role; some users (for example, an admin who's also active in Projects) have several.

Tenant roles are assigned by your tenant admin from **Settings → Users**.

### 2. Project Membership

Even with a tenant role that allows Project access, **most users only see Projects they've been explicitly added to**. The exception is the highest admin tiers (Super Admin, Company Admin, Codifi Admin), which see every Project in the tenant by default.

Project membership is managed from inside each Project — see [Project Members](/codifi-docs/cross-platform-features/project-members.md).

{% hint style="info" %}
**This is the most common source of confusion.** A user who has the right role can still find that a teammate's Project is invisible to them — because they haven't been added to it yet. Adding them to **Project Members** fixes it instantly.
{% endhint %}

***

## The Roles

Codifi tenants have eight user-assignable roles, plus a Codifi-internal admin role you'll see referenced but won't assign yourself.

| Role              | Who It's For                                                                                                                                                                                                                                                                                                                                    |
| ----------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Super Admin**   | The top tenant administrator. Full access to settings, users, the Library, every Project, and analytics. Reserved for whoever owns the tenant on your team.                                                                                                                                                                                     |
| **Company Admin** | Senior leadership. Wide visibility into Projects and analytics, plus user management — without the depth of access Super Admin has into low-level tenant configuration.                                                                                                                                                                         |
| **User Admin**    | Manages people. Can view the user list, invite users, edit users, deactivate users, and assign roles to existing users — though they cannot assign the highest-tier roles (Super Admin, Composer, Company Admin) or the Guest role. **Re-activating a deactivated user (and force-setting passwords) is reserved for Company Admin and above.** |
| **Composer**      | Composition authors. The only non-admin role with **edit access to the Library** — archetypes, fields, value lists, status workflows, Ripple formulas, map symbology, and Composition publishing all live behind this role.                                                                                                                     |
| **Data Admin**    | Data stewards. Has tenant-wide visibility into Projects and access to **Settings**, plus on mobile can manage Record assignees across Projects. Used when someone needs cross-Project data oversight without being a full Project lead or library author.                                                                                       |
| **Project Admin** | Project leads. Creates and configures Projects, manages Project members, sets up map overlays and offline areas, and reviews or exports Project data. Has access to **Settings** for tenant-level configuration. The everyday "set up a Project for a field crew" role.                                                                         |
| **Team Member**   | Field crew and analysts. Captures Records, edits Records they have access to, captures and reviews media, runs reports. Project Members visibility is required.                                                                                                                                                                                 |
| **Guest**         | View-only access. Can see Records and media on Projects they're added to but cannot create, edit, or export. Useful for clients, reviewers, or auditors.                                                                                                                                                                                        |

There's also a **Codifi Admin** role used by Codifi support staff for cross-tenant assistance. It's not assigned by tenant admins and is invisible to most users.

***

## What Each Role Can Do — At a Glance

The exact feature-by-feature permission breakdown lives inside the web app. To see it:

1. Open the user menu (your avatar in the top-right).
2. Click **Roles & Permissions**.
3. The Roles & Permissions modal shows every feature in the product, what permission each requires, and which roles have that permission. Use the modal as the source of truth — it always reflects the current build.

***

## Common Scenarios

### "I added a teammate but they don't see the Project"

They probably need to be added to **Project Members** for that specific Project. Tenant role alone doesn't grant Project visibility for most roles. See [Project Members](/codifi-docs/cross-platform-features/project-members.md).

### "I invited a teammate but they don't show up in Project Members"

The invite is probably still pending. Until the user accepts the invitation and creates their password, they're not selectable in the Project Members picker. See [Inviting Users to Codifi](/codifi-docs/getting-started/inviting-users-to-codifi.md).

### "I want a teammate to build Compositions but not see Tenant settings"

Assign them the **Composer** role. Composer covers the full Library — archetypes, fields, value lists, status workflows, Ripple formulas, and Composition publishing — and does not unlock Tenant Settings. There's no need to pair it with Data Admin for Library editing.

### "A client needs to see field data without being able to edit anything"

Invite them as a **Guest** and add them to the relevant Projects. Guests can see Records and media but cannot create, edit, or export.

### "Our office director needs to see analytics across all Projects"

Assign them **Company Admin**. This gives broad visibility (every Project in the tenant + analytics) without the lower-level tenant configuration access of Super Admin.

***

## Multiple Roles on One User

A single user can hold more than one role. When that happens, **the union of all their roles' permissions applies** — so a user with both Composer and Project Admin can do anything either role can do.

This is useful for hybrid jobs: a Project lead who also builds Compositions, or a User Admin who's also the Super Admin's backup. Use it sparingly — the cleanest org setup pairs each user with the smallest set of roles that covers their work.

***

## Who Can Change Roles

Only **Super Admin** and **User Admin** can assign or change roles. If your role doesn't fit your responsibilities, message your tenant's Super Admin.

Codifi staff cannot change role assignments inside your tenant — that authority lives entirely with your tenant admins.

***

## See Also

* [Inviting Users to Codifi](/codifi-docs/getting-started/inviting-users-to-codifi.md) — how to add a new person to your tenant
* [Project Members](/codifi-docs/cross-platform-features/project-members.md) — how to add tenant users to a specific Project
