Cognis

Roles & scopes

Default system roles for organization members are defined in the Cognis policy package. Each cell shows whether that role grants the scope. Owner and Super admin receive the full scope registry. Admin receives the same set except team member removal, billing write, integration delete, storefront domain delete, and webhooks write. Manager receives the same set except team administration (create/delete), org settings write, billing write, and all organization integration scopes (integrations are limited to owner, super admin, and admin). Member is the day-to-day operator role — all read scopes from the registry (minus integrations and LAP submissions) plusorg:grid:rows:write (task status moves) and org:chat:write; promote to Manager for anyone who needs to edit content. Custom roles created for an org can differ; this page documents only built-in system roles.

ScopeOwnerSuper AdminAdminManagerMemberContributorBillingViewer
org:read
org:brands:read
org:brands:write
org:brands:create
org:brands:delete
org:team:read
org:team:write
org:team:create
org:team:delete
org:settings:read
org:settings:write
org:integrations:read
org:integrations:write
org:integrations:create
org:integrations:delete
org:meta:read
org:meta:write
org:meta:create
org:meta:delete
org:meta:manage
org:signals:read
org:signals:write
org:signals:create
org:signals:delete
org:directives:read
org:directives:write
org:directives:create
org:directives:delete
org:inbox:read
org:inbox:write
org:dashboards:read
org:dashboards:write
org:dashboards:create
org:dashboards:delete
org:dashboards:manage
org:schemas:read
org:schemas:write
org:schemas:create
org:schemas:delete
org:frameworks:read
org:frameworks:write
org:frameworks:create
org:frameworks:delete
org:templates:read
org:templates:write
org:templates:create
org:templates:delete
org:audience:read
org:audience:write
org:audience:avatars:read
org:audience:avatars:write
org:audience:avatars:create
org:audience:avatars:delete
org:audience:problems:read
org:audience:problems:write
org:audience:problems:create
org:audience:problems:delete
org:audience:research_insights:read
org:audience:research_insights:write
org:audience:research_insights:create
org:audience:research_insights:delete
org:billing:read
org:billing:write
org:billing:portal
org:docs:read
org:docs:write
org:docs:create
org:docs:delete
org:blog:read
org:blog:write
org:blog:create
org:blog:delete
org:lap:sites:read
org:lap:sites:create
org:lap:submissions:read
org:airuns:read
org:airuns:write
org:airuns:create
org:airuns:delete
org:test_runs:read
org:test_runs:write
org:test_runs:create
org:test_runs:delete
org:creatives:read
org:creatives:write
org:landing_pages:read
org:landing_pages:write
org:grid:grids:read
org:grid:grids:create
org:grid:grids:write
org:grid:sections:create
org:grid:sections:write
org:grid:sections:delete
org:grid:rows:read
org:grid:rows:create
org:grid:rows:write
org:grid:rows:delete
org:grid:variants:create
org:grid:variants:write
org:grid:variants:delete
org:grid:row_types:read
org:grid:row_types:create
org:grid:row_types:write
org:grid:row_types:delete
brand:read
brand:write
brand:create
brand:delete
brand:products:read
brand:products:write
brand:products:create
brand:products:delete
brand:settings:read
brand:settings:write
brand:scrollstoppers:read
brand:scrollstoppers:write
brand:scrollstoppers:create
brand:scrollstoppers:delete
brand:product_images:read
brand:product_images:write
brand:product_images:create
brand:product_images:delete
brand:urls:read
brand:urls:write
brand:urls:create
brand:urls:delete
brand:creative_views:read
brand:creative_views:write
brand:creative_views:create
brand:creative_views:delete
brand:creative_views:manage
brand:creatives:read
brand:creatives:write
brand:creatives:variant_media:write
brand:creatives:create
brand:creatives:delete
brand:designProposals:read
brand:designProposals:write
product:read
product:write
product:create
product:delete
product:settings:read
product:settings:write
collection:read
collection:write
collection:create
collection:delete
org:chat:read
org:chat:write
org:chat:manage
org:invoices:read
org:invoices:write
org:invoices:create
org:invoices:manage
org:invoices:delete
org:bonuses:read
org:bonuses:write
org:webhooks:read
org:webhooks:write
org:ecom:read
org:ecom:write
org:ecom:settings:read
org:ecom:settings:write
org:ecom:domain:read
org:ecom:domain:write
org:ecom:domain:create
org:ecom:domain:delete
org:ecom:collections:read
org:ecom:collections:write
org:ecom:collections:create
org:ecom:collections:delete
org:ecom:translations:read
org:ecom:translations:write
org:settings:audit:read
org:settings:trash:read
org:settings:trash:write
org:mailbox:read
org:mailbox:write
org:mailbox:assign
org:mailbox:admin
org:ecom:create
org:custom_fields:read
org:custom_fields:write
meta:ads:claim
meta:launch:execute
org:ecom:checkout:read
org:ecom:checkout:write
org:table_views:read
org:table_views:write

Policy version 126 (role definitions and scope registry are versioned together in code).