Download Reportworq
⬇ Guide PDF

Roles and what you can do#

Reportworq tailors the app to each account. What a person sees, the side rail, the toolbars, the actions on a row, is decided by their role. Two things combine to produce what an account can actually do:

An account's effective access is the role constrained by the permissions on each item. This page is a reference to the roles themselves.

The four roles#

Reportworq has three licensed roles, Administrator, Author, and User, and one role that is not a license at all: the Recipient, who simply receives distributed content. Every person who signs in holds exactly one licensed role, and that role applies across the whole installation (you are not an Author in one workspace and a User in another).

Role Licensed Lands in Can Cannot
Administrator Yes (seat) The full shell plus Settings Everything: manage security, users, integrations, connections, content, and licensing; reaches every workspace (System-wide reach depends on administrator tier, see below)
Author Yes (seat) The full Workspace shell Create, edit, run, schedule, and monitor reports, campaigns, and data models where their permissions allow; use the Excel authoring add-in; use global search; see (read-only) who has access to an item Reach system settings unless also an administrator; see content outside the workspaces and folders granted to them; change anyone's permissions
User Yes (seat) A read-only Workspace, with My Input Forms added to the side rail when they are assigned to a contribution campaign View permitted folders, reports, and outputs by ACL; fill in and submit contribution forms; refresh distributed PowerPoint decks in the add-in; reach content through the MCP server and the built-in AI assistant Create or edit reports; the New button, authoring toolbar, and header search box are absent
Recipient No (not an entitlement) Nothing, they never sign in Receive distributed output wherever they already work, email, Slack, Teams, SharePoint, a network folder, and more Sign in to Reportworq, or see anything beyond what is delivered to them

What each role sees#

Recipient is a concept, not a setting. "Recipient" describes anyone who receives distributed content without a login. There is no Recipient entitlement to grant and no Recipient seat to buy; you never assign it in Security. Sending an output to someone does not require them to have a Reportworq role. See Address book and contacts.

Who can see and change permissions#

An item's permissions, the list of accounts and groups that can see a folder, a report, or the workspace as a whole, are themselves governed by role.

Role Can see permissions Can change permissions
User No, anywhere. Properties shows the Overview tab only, with no Security tab. No
Author Yes, read-only, everywhere they are shown. No
Administrator Yes Yes

As an Author you can open the Security tab of any item you can reach and see exactly who has access, which is often what you need in order to answer "why can't they see my report". The list is read-only: there is no Save, no way to add an account or group, and no way to remove one. Changing access is an administrator task, so ask an administrator.

This holds however you reach a security surface, including from a saved link or browser history.

Earlier role names fold in#

If you are reading older documentation, license notes, or an account export, several retired names map onto the three current roles:

Administration and workspace access#

Administration is not tiered. The Administrator role has full access to every workspace on the server regardless of individual grants, and it governs roles and cross-workspace scope. There is no per-workspace administrator: Settings, including datasource configuration, is Administrator-only.

Within a workspace there is one kind of grant: everyone listed on a workspace is a member, and a member can reach the workspace and its content as their item permissions allow. There is no second level to choose.

Workspace membership decides whether an account can enter a workspace; per-item permissions decide which items inside it the account can see and act on.

If you are looking for Configuration Access. Earlier versions offered a second workspace level, Configuration Access (sometimes called Workspace Administrator), that allowed datasource management inside one workspace. It has been removed. Member is the only level.

Notes and limits#

Feedback on this page

Comments, questions, requests, or something missing or unclear? Email us - the page you are on is filled in for you.

Email feedback on this page

Or write to support@reportworq.com directly.