Understand roles and permissions

Control who can do what with role presets for your team and a separate portal-only role for customers.

DU
Demo User
Written By Demo UserLast updated 2 months ago

Give your team the access they need without exposing settings to everyone. Quackback separates your customers from your team, and gives your team a role that determines exactly what they can configure.

Overview

Everyone who interacts with your Quackback workspace is either a Portal User (a customer) or a team member with one of four roles.

Type

Who they are

How they get access

Portal User

Your customers and end users

Sign up through the public portal

Team member

Your teammates who manage feedback and support

Invited by an admin and assigned a role

Note:
Team members can also use the public portal like regular Portal Users. They don't need a separate account.

Team member roles

Quackback ships four role presets, from broadest to narrowest access:

Role

What it grants

Owner

Full access, including billing and role management

Admin

Full access except billing

Manager

Configures and operates the whole product and inbox, but not workspace-level settings

Contributor

Works feedback and support queues day to day, without configuring product structure or settings

Warning:
Every workspace needs at least one Owner. You cannot remove or demote the last one.

See exactly what each role can do

The Roles tab in Members & Teams shows the permission catalogue behind every role: roughly 90 individual permissions grouped by area, including workspace settings, people, companies, feedback, conversations, changelog, help center, and integrations. Expand a role there to see precisely which permissions it grants.

Custom roles

When none of the presets is quite right, create your own role from the Roles tab. Custom roles grant any mix of catalogue permissions and are assignable everywhere a preset is: the member list, invites, and the REST API.

Create one:

  1. Go to Admin -> Settings -> Members & Teams -> Roles
  2. Click New role, or Duplicate on any existing role to start from its permissions
  3. Name it and pick permissions in the editor - the 15 catalogue categories each have a select-all, and you can filter by key

The rules that keep custom roles safe:

  • Built-in roles are read-only. Duplicate one to customize it; the presets themselves never change.
  • You can only grant permissions you hold. Duplicating a richer role leaves the extra permissions off (the editor tells you how many), and the same ceiling applies when assigning a role to someone or choosing where members land when a role is deleted.
  • You can't edit or delete a role you currently hold, so nobody can lock themselves out or quietly upgrade their own access.
  • Deleting an in-use role requires a destination. You choose the role its members move to; nobody silently loses workspace access.

Note:
When a Quackback update ships new permissions, the built-in roles pick them up automatically but custom roles do not - new permissions are off until you opt in. The role editor badges anything added since the role's last edit, so a quick review after upgrading is all it takes.

Custom roles hold the Member tier for seat and access purposes; the Owner tier stays exclusive to the built-in promotion path.

Assign a custom role

  • Existing member: Members & Teams -> the ... menu on their row -> Change role -> pick the role under Custom
  • New teammate: choose the role in the invite dialog; they hold it from the moment they accept
  • API: PATCH /api/v1/principals/:id with a roleId

Portal Users

Portal Users are your customers. They interact with Quackback through the public-facing feedback portal, not the admin dashboard.

How they sign up: Portal Users create an account on your portal using the authentication methods you configure - email OTP, OAuth, or SSO.

What they can do:

  • Submit feedback and bug reports
  • Vote on posts they care about
  • Comment on any post
  • Edit and delete their own posts
  • Browse the public roadmap and changelog

Tip:
Portal Users are unlimited. Encourage your entire user base to sign up and submit feedback.

Team members

Team members are your teammates. They have everything Portal Users have, plus access to the admin dashboard, scoped to what their role permits.

How they join: An admin or owner invites them by email and assigns a role. They receive a link to join the workspace.

What they can typically do beyond Portal Users, depending on role:

  • Access the admin dashboard and feedback inbox
  • Change post statuses, merge duplicates, and assign owners
  • Add tags and manage roadmap items
  • Post private internal comments and handle support conversations
  • Create changelog entries
  • Manage boards, statuses, and tags

Only Owners and Admins can change workspace settings, manage integrations, or invite other team members.

Change roles

Promote, demote, or reassign team members at any time from Members & Teams.

  1. Go to Admin → Settings → Members & Teams
  2. Find the member in the list
  3. Click the ... menu on their row
  4. Select a new role

Changes take effect immediately and don't affect the member's existing comments, posts, or activity history.

To convert a team member back to a Portal User, remove them from the team entirely. They keep their portal account and can still submit feedback.

Next steps

Was this helpful?

Your feedback shapes what we write next.