Skip to main content

User Roles

Every member of your organization on Panto AI has a role that determines what they can see and do inside the dashboard. Roles are assigned when a member is invited, and can be changed later by an admin.

Here we cover the three roles a member can hold day-to-day: Guest, User, and Admin.


Roles at a Glance​

RoleCan view org dataCan create/run testsCan manage integrations & toolsCan manage team members
Guest✅❌❌❌
User✅✅✅❌
Admin✅✅✅✅

Guest​

Guests have read-only access to the organization. They're a good fit for stakeholders who need visibility into testing activity without being able to change anything.

A Guest can:

  • View the app builds list and details
  • View test flows, test suites, and their run history
  • View test run results, logs, videos, and session history
  • View environments and their variables
  • View connected integrations, their status, and tools

A Guest cannot:

  • Upload or delete app builds
  • Create, edit, delete, or trigger test flows or test suites
  • Create or modify environments or environment variables
  • Connect, update, or disconnect integrations (Slack, Webhook, Telegram, Database)
  • Create, edit, delete, or execute tools
  • Generate or manage API keys
  • Invite, edit, or remove team members

Any attempt by a Guest to perform one of the actions above is blocked with an authorization error.


User​

Users have full working access to the organization's testing workflows, but no control over team membership.

A User can do everything a Guest can, plus:

  • Upload and delete app builds
  • Create, edit, delete, and trigger test flows and test suites
  • Save recordings as test flows, regenerate static code, and edit generated test code
  • Create app contexts (including code-gen context) and manage them
  • Create, edit, and delete environments and environment variables
  • Connect, update, and disconnect integrations (Slack, Webhook, Telegram, Database)
  • Create, edit, delete, and execute custom tools (API and DB tools)
  • Generate, list, and delete API keys
  • Abort and refresh test runs

A User cannot:

  • Invite new members to the organization
  • Change another member's role
  • Remove a member from the organization

Admin​

Admins have every permission a User has, plus full control over the organization's membership.

An Admin can additionally:

  • Invite new members to the organization, assigning them the Guest, User, or Admin role
  • Change a member's role between Guest, User, and Admin
  • Remove a member from the organization

A few guardrails apply to keep an organization from being locked out or mismanaged:

  • An Admin cannot change their own role or remove themselves from the organization — this must be done by another Admin.
  • An Admin cannot promote a member directly to Super Admin, and cannot edit or remove an existing Super Admin.
  • An Admin cannot remove the organization's last remaining Admin — there must always be at least one Admin left in the org.

Managing Roles​

Role management lives on the Teams page of the dashboard, and is only available to Admins.

Inviting a member​

  1. Go to the teams page.
  2. Click Invite User.
  3. Enter the member's name and email.
  4. Choose a role — Guest, User, or Admin.
  5. Click Send Invite.

The invited member receives an email with a link to log in and join the organization. They start off as "not joined" until they log in for the first time.

Changing a member's role​

  1. Find the member in the team list.
  2. Update their role to Guest, User, or Admin.

The change takes effect immediately — the member's permissions update the next time they load the dashboard.

Removing a member​

  1. Find the member in the team list.
  2. Remove them from the organization.

You'll be asked to confirm — this can't be undone, and the member will lose access to the organization immediately.