> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truagents.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions matrix

> Reference outline for documenting which roles and account types can access which TruAgents capabilities.

## Summary

This page should become the fast lookup for role and access questions in TruAgents.

The current app clearly distinguishes between general authenticated users, admins, public report viewers, and internal-only or admin-only surfaces. That means a permissions reference is worth having even before the final matrix is fully complete.

## What this page should eventually answer

| Question type          | Example                                              |
| ---------------------- | ---------------------------------------------------- |
| Workspace access       | Who can manage organization defaults?                |
| Team access            | Who can add or edit teammates?                       |
| Workflow access        | Who can create campaigns or review communications?   |
| Reporting access       | Who can see in-app analytics versus public reports?  |
| Technical/admin access | Which settings or controls are restricted to admins? |

## Important distinctions to preserve

* Authenticated app access versus token-based public report access
* Self-service profile changes versus admin-managed access changes
* General user workflows versus admin-only controls

## What we can say safely already

Even before the full validated matrix is complete, the current product clearly implies these broad distinctions:

| Access area                               | Likely boundary                                |
| ----------------------------------------- | ---------------------------------------------- |
| Profile updates and password reset        | Self-service user account area                 |
| Team membership and teammate roles        | Owner/admin-style responsibility               |
| Organization defaults and sensitive setup | Restricted admin responsibility                |
| Public report viewing                     | Tokenized external access, not full app access |

## How to use this page today

Use this reference to classify the kind of access question first.

Then go deeper into the related page for the actual workflow:

* self-service account questions -> [Profile and account access](/admin/profile-and-account-access)
* teammate/role questions -> [Team management](/admin/team-management)
* org-level restriction questions -> [Organization settings](/admin/organization-settings)
* external report access questions -> [Report sharing model](/reference/report-sharing-model)

Simple version: this page is the map, not the whole journey.

## What not to overclaim yet

Until the final matrix is validated from real product behavior, avoid pretending this page is an exhaustive source of truth for every single role/action combination.

That is better than shipping a precise-looking matrix that is quietly wrong.

## Current documentation status

This page is still a structured outline. The final matrix should be based on validated product behavior rather than guessed role semantics.

## Related pages

* [Permissions and access](/support/permissions-and-access)
* [Team management](/admin/team-management)
* [Organization settings](/admin/organization-settings)
* [Profile and account access](/admin/profile-and-account-access)
* [Report sharing model](/reference/report-sharing-model)
