# Roles & Access
Every user has one base role and, optionally, extra permissions for sensitive work. Admins set both in Settings → Users. See User Management for inviting and deactivating users.
# Base roles
Each role includes everything in the one above it.
| Role | Can do |
|---|---|
| Viewer | View operational records. |
| Contributor | View and edit operational records: batches, inventory, orders, movements. |
| Manager | Contributor access, plus reports and manager workflows. |
| Administrator | Full access, including users, settings and integrations. Administrators have every permission. |
The person who creates the account is an administrator. The last active administrator cannot be deactivated or downgraded until another administrator is assigned.
# Permissions
A Viewer, Contributor or Manager can be given any of these with Add Permission:
| Permission | Allows |
|---|---|
| Inventory Admin | Inventory setup and administrative corrections, such as opening inventory and audit corrections. |
| Barrels: Correct State | Manually correcting historical barrel contents and status. |
| COGS: View | Viewing cost-of-goods information, including the Profitability Planner. |
| COGS: Edit | Viewing and editing cost-of-goods information. |
Give a permission to the person who does that job rather than raising their base role.
# Domain enrollment
Domain enrollment adds Google users from your email domain automatically, with a default base role and permissions. Those are granted the moment an eligible person first signs in, so choose them carefully. See Domain Enrollment.
# Audit
Creating users, changing their access, invitations, deactivation and reactivation are recorded in an access audit that cannot be edited.