Skip to main content

User Roles

Every member of your organization on Panto AI has a role that determines what they can see and do inside the dashboard. Roles are assigned when a member is invited, and can be changed later by an admin.

Here we cover the three roles a member can hold day-to-day: Guest, User, and Admin.


Roles at a Glance

RoleCan view org dataCan create/run testsCan manage integrations & toolsCan manage team members
Guest
User
Admin

Guest

Guests have read-only access to the organization. They're a good fit for stakeholders who need visibility into testing activity without being able to change anything.

A Guest can:

  • View the app builds list and details
  • View test flows, test suites, and their run history
  • View test run results, logs, videos, and session history
  • View environments and their variables
  • View connected integrations, their status, and tools

A Guest cannot:

  • Upload or delete app builds
  • Create, edit, delete, or trigger test flows or test suites
  • Create or modify environments or environment variables
  • Connect, update, or disconnect integrations (Slack, Webhook, Telegram, Database)
  • Create, edit, delete, or execute tools
  • Generate or manage API keys
  • Invite, edit, or remove team members

Any attempt by a Guest to perform one of the actions above is blocked with an authorization error.


User

Users have full working access to the organization's testing workflows, but no control over team membership.

A User can do everything a Guest can, plus:

  • Upload and delete app builds
  • Create, edit, delete, and trigger test flows and test suites
  • Save recordings as test flows, regenerate static code, and edit generated test code
  • Create app contexts (including code-gen context) and manage them
  • Create, edit, and delete environments and environment variables
  • Connect, update, and disconnect integrations (Slack, Webhook, Telegram, Database)
  • Create, edit, delete, and execute custom tools (API and DB tools)
  • Generate, list, and delete API keys
  • Abort and refresh test runs

A User cannot:

  • Invite new members to the organization
  • Change another member's role
  • Remove a member from the organization

Admin

Admins have every permission a User has, plus full control over the organization's membership.

An Admin can additionally:

  • Invite new members to the organization, assigning them the Guest, User, or Admin role
  • Change a member's role between Guest, User, and Admin
  • Remove a member from the organization

A few guardrails apply to keep an organization from being locked out or mismanaged:

  • An Admin cannot change their own role or remove themselves from the organization — this must be done by another Admin.
  • An Admin cannot promote a member directly to Super Admin, and cannot edit or remove an existing Super Admin.
  • An Admin cannot remove the organization's last remaining Admin — there must always be at least one Admin left in the org.

Managing Roles

Role management lives on the Teams page of the dashboard, and is only available to Admins.

Inviting a member

  1. Go to the teams page.
  2. Click Invite User.
  3. Enter the member's name and email.
  4. Choose a role — Guest, User, or Admin.
  5. Click Send Invite.

The invited member receives an email with a link to log in and join the organization. They start off as "not joined" until they log in for the first time.

Changing a member's role

  1. Find the member in the team list.
  2. Update their role to Guest, User, or Admin.

The change takes effect immediately — the member's permissions update the next time they load the dashboard.

Removing a member

  1. Find the member in the team list.
  2. Remove them from the organization.

You'll be asked to confirm — this can't be undone, and the member will lose access to the organization immediately.