The roles
| Role | Who they are | Access |
|---|---|---|
Administrator (TENANT_ADMIN) |
Customer admin | Everything in the tenant: configures, creates and edits across all modules |
Manager (TENANT_MANAGER) |
Area / HR manager | Creates campaigns and tracks them; read access in the People module |
Ombudsman (TENANT_OMBUDSMAN) |
Whistleblowing channel | Sees only compliance reports (whistleblowing) |
Collaborator (COLLABORATOR) |
Collaborator | Only the collaborator portal / desktop agent; no access to the web console |
Super Admin (SUPER_ADMIN) |
qlture team | Global access; administers tenants. Does not belong to any tenant |
What each one can do
General rule: the Administrator writes; the Manager reads (and creates campaigns/content). Sensitive actions require an Administrator.
| Area | Administrator | Manager | Collaborator |
|---|---|---|---|
| Users — view | ✅ | ✅ | ❌ |
| Users — invite/edit/deactivate/import | ✅ | ❌ | ❌ |
| Groups and departments — view | ✅ | ✅ | ❌ |
| Groups and departments — create/edit/remove | ✅ | ❌ | ❌ |
| Content library — create/edit | ✅ | ✅ | ❌ |
| Content — archive / delete quiz | ✅ | ❌ | ❌ |
| Campaigns (training/phishing) — view | ✅ | ✅ | ❌ |
| Campaigns — create/publish/edit/cancel | ✅ | ❌ | ❌ |
| SSO, SCIM, Self-enrollment | ✅ | ❌ | ❌ |
| Audit log | ✅ | ❌ | ❌ |
| Compliance reports (whistleblowing) | ❌* | ❌* | ❌ |
* Compliance reports are exclusive to the Ombudsman (and the Super Admin). Neither Administrator nor Manager can see them, to preserve the confidentiality of the channel. All other reports (security, social engineering) go to the Administrator/Manager.
Security rules that apply to everyone
- Tenant isolation. No data leaks between organizations; the tenant always comes from the session, never from the form.
- No one becomes a Super Admin through an invite or promotion — it’s blocked.
- Deactivation ends sessions immediately (soft delete + token revocation).
- Collaborators have no password by default: they sign in via email OTP.
Related
</content>