Two Minute Reports Logo
Roles & Permissions

The Six Standard Roles

Owner, Admin, Deputy Admin, Data Manager, Editor and Viewer — what each role is for, what it cannot do, and how to choose between them.

Every team comes with six roles. What they can do nests — each role includes everything the smaller ones can — but they are not six levels of seniority. They are six different jobs, and the two in the middle exist because setting data up and building reports on it are usually done by different people. A Data Manager is not a junior Deputy Admin; they are the person who owns the connections.

You can see all six in the Hub at Settings → Roles, along with any your team has built for itself.

Clicking a role opens a grid of all 71 permissions, grouped by area, showing what the role includes and what it does not. The second half is the more useful one: "why can't this person do X" is answered by finding X unticked.

At a Glance

Smallest first. Each role can do everything in every row above it, plus its own additions — so reading down the table accumulates, and no row repeats what an earlier one already said.

RoleWho it is forWhat it adds
ViewerStakeholders and colleagues who only need to lookReads everything the team has — dashboards, reports, clients, the queries in a sheet
EditorReport builders working on data someone else set upBuilds the work: dashboards, goals, briefings, sheet queries and schedules, Studio query configs
Data ManagerWhoever owns the connections and the data setupThe setup everyone else builds on: connections, connected accounts, which accounts belong to which client, custom fields, brand themes
Deputy AdminAn operations lead who runs the team and owns the client listThe client roster — adding and removing clients — and running the team: invites, roles, seats, team settings, plus the plan and the audit log
AdminA co-owner you would trust to end the contractBilling and custom roles: changing the plan, payment details, cancelling
OwnerThe person the subscription belongs toNothing — identical permissions to Admin. What differs is that nobody can remove or re-role them

To read what a role cannot do, look at the rows below it. An Editor cannot add a connection because that is Data Manager's row; a Data Manager cannot add a new client or invite anyone because both are Deputy Admin's. Nothing is withheld from Admin or Owner.

The permissions matrix has the exact lists, all 71 of them, with the roles side by side.

Viewer

Reads everything the team has and changes nothing. Viewers can open dashboards, see clients and reports, and read the queries in a sheet — but every control that would change something is unavailable to them.

Viewers do not see the plan, invoices or billing. They also cannot run a query on demand, because each run calls the ad platform and costs money.

Give this to stakeholders and anyone whose job is to look. Not to clients — they are given access by sharing a report with them, not by joining the team.

Editor

Builds reports on data somebody else set up: dashboards, goals, Google Sheets queries and schedules, Looker Studio query configs, briefings.

An Editor cannot add a connection, enable a connected account, map an account to a client, or define a custom field. That is not a restriction on their competence — it is that those actions have consequences beyond their own work. Enabling an account consumes a plan limit and costs money; removing a connection breaks every report drawing on it.

This is the default role for most people who do the work.

Data Manager

Owns the setup. Connections, connected accounts, account mapping, custom fields and brand themes — everything that has to exist before anyone can build a report. Plus everything an Editor can do.

Adding a client is not part of this role; mapping accounts to one is. A Data Manager decides which connected accounts feed which client — which is what every client-scoped report contains — but cannot create a new client or delete an existing one. Deciding who your clients are sits with Deputy Admin and above.

No team administration either: a Data Manager cannot invite anyone, change a role, or assign a seat.

In an agency this is usually the person who onboards a new client's ad accounts once someone has added the client.

Deputy Admin

Runs the team and owns the client list: invites people, sets their roles, assigns and un-assigns seats, changes team settings, adds and removes clients, and does everything a Data Manager and Editor can do.

Adding a client is here rather than with Data Manager because it is a decision about the business rather than about data — "we have taken on this client" — and it is the same person who decides who joins the team.

Holds two permissions fewer than Admin. A Deputy Admin cannot change the plan — no buying seats, altering payment details or cancelling — though they can see what the plan is and how much of it is used, so they know when to come and ask. And they cannot create or edit roles, which is what stops somebody building a custom role to give themselves the first one.

This is the right role for an operations manager, a team lead, or whoever actually onboards people.

Admin

Everything the Owner can do, including changing the plan and cancelling the subscription. The difference is not a permission — an Admin holds exactly the same set — but that an Admin is a role somebody assigned, and can therefore be un-assigned.

Because the two sets are identical, one Admin cannot change or remove another: roles are only editable downwards and equal does not count as below. The account Owner can, and is the only person who can. If you need an Admin removed and you are not the Owner, the Owner has to do it.

Give this to a business partner or a co-founder — someone you would trust to end the contract.

An Admin can cancel the subscription and change the payment method. If that is more than you meant to hand over, Deputy Admin is almost certainly the role you want.

Owner

The person whose email the subscription is under. The Owner holds every permission and is the one role nobody else can touch: they cannot be removed, cannot be given a different role, and do not need a seat of their own to change the plan or hand out seats.

That last part is deliberate. If the Owner needed a seat to assign seats, a team that ran out of seats could never assign another one.

The Owner follows the account, not the person — it is not a role you hand out. To change who it is, contact [email protected].

How to Choose

Two questions get it right almost every time:

  1. Do they set data up, or build on data that is already there? Setting up is Data Manager; building on it is Editor.
  2. Do they decide who your clients are, or only which accounts belong to them? Adding and removing clients is Deputy Admin; mapping accounts to a client that already exists is Data Manager.
  3. Do they need to add and remove people? If yes, Deputy Admin. If they also need to change the plan, Admin.
When you are unsure, pick the smaller role. Widening it later is one dropdown, and nobody minds being given more access. Discovering that a new starter deleted a connection on their second day is a different conversation.

If none of the six fit, build a custom role with exactly the permissions you want.

Roles and Seats Are Separate

Assigning a role does not give someone a seat. A member with the Editor role and no seat sees the whole Hub and can change none of it — every editing control is disabled with an explanation.

That combination is useful on purpose: it is how you give a colleague full visibility of the reports without spending a seat on them. But if you have given someone a role and they tell you nothing works, check their seat first.

Copyright © 2026