Understand roles and permissions
Control who can do what with role presets for your team and a separate portal-only role for customers.
Give your team the access they need without exposing settings to everyone. Quackback separates your customers from your team, and gives your team a role that determines exactly what they can configure.
Overview
Everyone who interacts with your Quackback workspace is either a Portal User (a customer) or a team member with one of four roles.
Type | Who they are | How they get access |
|---|---|---|
Portal User | Your customers and end users | Sign up through the public portal |
Team member | Your teammates who manage feedback and support | Invited by an admin and assigned a role |
Note:
Team members can also use the public portal like regular Portal Users. They don't need a separate account.
Team member roles
Quackback ships four role presets, from broadest to narrowest access:
Role | What it grants |
|---|---|
Owner | Full access, including billing and role management |
Admin | Full access except billing |
Manager | Configures and operates the whole product and inbox, but not workspace-level settings |
Contributor | Works feedback and support queues day to day, without configuring product structure or settings |
Warning:
Every workspace needs at least one Owner. You cannot remove or demote the last one.
See exactly what each role can do
The Roles tab in Members & Teams shows the permission catalogue behind every role: roughly 90 individual permissions grouped by area, including workspace settings, people, companies, feedback, conversations, changelog, help center, and integrations. Expand a role there to see precisely which permissions it grants.
Custom roles
When none of the presets is quite right, create your own role from the Roles tab. Custom roles grant any mix of catalogue permissions and are assignable everywhere a preset is: the member list, invites, and the REST API.
Create one:
- Go to Admin -> Settings -> Members & Teams -> Roles
- Click New role, or Duplicate on any existing role to start from its permissions
- Name it and pick permissions in the editor - the 15 catalogue categories each have a select-all, and you can filter by key
The rules that keep custom roles safe:
- Built-in roles are read-only. Duplicate one to customize it; the presets themselves never change.
- You can only grant permissions you hold. Duplicating a richer role leaves the extra permissions off (the editor tells you how many), and the same ceiling applies when assigning a role to someone or choosing where members land when a role is deleted.
- You can't edit or delete a role you currently hold, so nobody can lock themselves out or quietly upgrade their own access.
- Deleting an in-use role requires a destination. You choose the role its members move to; nobody silently loses workspace access.
Note:
When a Quackback update ships new permissions, the built-in roles pick them up automatically but custom roles do not - new permissions are off until you opt in. The role editor badges anything added since the role's last edit, so a quick review after upgrading is all it takes.
Custom roles hold the Member tier for seat and access purposes; the Owner tier stays exclusive to the built-in promotion path.
Assign a custom role
- Existing member: Members & Teams -> the ... menu on their row -> Change role -> pick the role under Custom
- New teammate: choose the role in the invite dialog; they hold it from the moment they accept
- API:
PATCH /api/v1/principals/:idwith aroleId
Portal Users
Portal Users are your customers. They interact with Quackback through the public-facing feedback portal, not the admin dashboard.
How they sign up: Portal Users create an account on your portal using the authentication methods you configure - email OTP, OAuth, or SSO.
What they can do:
- Submit feedback and bug reports
- Vote on posts they care about
- Comment on any post
- Edit and delete their own posts
- Browse the public roadmap and changelog
Tip:
Portal Users are unlimited. Encourage your entire user base to sign up and submit feedback.
Team members
Team members are your teammates. They have everything Portal Users have, plus access to the admin dashboard, scoped to what their role permits.
How they join: An admin or owner invites them by email and assigns a role. They receive a link to join the workspace.
What they can typically do beyond Portal Users, depending on role:
- Access the admin dashboard and feedback inbox
- Change post statuses, merge duplicates, and assign owners
- Add tags and manage roadmap items
- Post private internal comments and handle support conversations
- Create changelog entries
- Manage boards, statuses, and tags
Only Owners and Admins can change workspace settings, manage integrations, or invite other team members.
Change roles
Promote, demote, or reassign team members at any time from Members & Teams.
- Go to Admin → Settings → Members & Teams
- Find the member in the list
- Click the ... menu on their row
- Select a new role
Changes take effect immediately and don't affect the member's existing comments, posts, or activity history.
To convert a team member back to a Portal User, remove them from the team entirely. They keep their portal account and can still submit feedback.
Next steps
- Manage your team - Invite members, assign roles, and set up teams
- Configure team security - Control sign-in methods
- Core Concepts - Review how roles fit into the bigger picture
Was this helpful?
Your feedback shapes what we write next.