> For the complete documentation index, see [llms.txt](https://docs.zephyrintel.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.zephyrintel.com/reference/permissions-reference.md).

# Permissions reference

Signal controls what you can do by checking a set of permission keys on your account. Displayed roles do not grant anything. This page lists each key and the full matrix of who can do what.

### Permission keys

| Permission key  | What it allows                                                                                                                                                        |
| --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `create`        | **New Asset** and **Bulk Import** in Empire View.                                                                                                                     |
| `edit`          | **Change Status** and **Duplicate** in the Empire View bulk action bar; **Change status**, the serial number edit pencil, and reassigning a customer on Asset Detail. |
| `delete`        | **Archive** in the Empire View bulk action bar. Archiving a single asset from Asset Detail does not require this permission (see note below).                         |
| `promote`       | The **Drafts** and **Archived** filter toggles in Empire View, and **Promote** and **Restore** in the bulk action bar.                                                |
| `admin panel`   | Changing the **Account Owner** on a customer's Edit Customer form.                                                                                                    |
| `read`, `write` | Recorded on your account but not currently used to show or hide anything in Signal.                                                                                   |

Note: archiving one asset from its own Asset Detail page only requires that your account has access to Signal and that the asset belongs to an organization you can act on. Archiving from the Empire View bulk action bar additionally requires the `delete` permission.

If you do not see a button described above, your account does not have the permission that allows it. Ask your administrator.

### Matrix

Columns describe five kinds of accounts: a user with no permissions, a user who has the listed permission, Zephyr staff, Zephyr staff with admin rights, and Zephyr staff who are currently viewing Signal as another user (simulating).

| Capability                                                                                                                              | No permissions                                                                  | With the permission                         | Zephyr staff                                          | Zephyr staff admin  | Staff simulating a user                                                    |
| --------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------- | ----------------------------------------------------- | ------------------- | -------------------------------------------------------------------------- |
| Sign in to Signal                                                                                                                       | Only with the Signal product on the account                                     | Only with the Signal product on the account | Yes                                                   | Yes                 | n/a                                                                        |
| See the **Org Admin** menu item                                                                                                         | No                                                                              | No                                          | Yes                                                   | Yes                 | Yes                                                                        |
| Open Organization Admin                                                                                                                 | No                                                                              | No                                          | Yes                                                   | Yes                 | No (sent to Dashboard)                                                     |
| Search and view organizations, hosts, and organization users                                                                            | No                                                                              | No                                          | Yes                                                   | Yes                 | No                                                                         |
| Upgrade an organization's products, offboard, reactivate, or unhost                                                                     | No                                                                              | No                                          | Yes                                                   | Yes                 | No                                                                         |
| Rename an organization's short name, edit its ownership policy, grant products to a user with **Elevate**, or merge organizations       | No                                                                              | No                                          | No (read-only)                                        | Yes                 | No                                                                         |
| Manage users and simulate a user in User Management                                                                                     | No                                                                              | No                                          | Yes                                                   | Yes                 | n/a (already simulating)                                                   |
| See data across every organization instead of just your own                                                                             | No                                                                              | No                                          | Only with platform-wide access granted to the session | Yes                 | No (scoped to the simulated organization)                                  |
| **New Asset** and **Bulk Import** in Empire View                                                                                        | No                                                                              | Yes (`create`)                              | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| **Drafts** and **Archived** filters in Empire View                                                                                      | No                                                                              | Yes (`promote` or `delete`)                 | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| **Promote** and **Restore** in the bulk action bar                                                                                      | No                                                                              | Yes (`promote`)                             | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| **Change Status** and **Duplicate** in the bulk action bar                                                                              | No                                                                              | Yes (`edit`)                                | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| **Archive** in the bulk action bar                                                                                                      | No                                                                              | Yes (`delete`)                              | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| **Export CSV** in the bulk action bar                                                                                                   | Yes                                                                             | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| **Archive** and **Duplicate** on Asset Detail's header menu                                                                             | Yes, if your account has Signal access and the asset has an owning organization | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| **Change status**, edit the serial number, and reassign a customer on Asset Detail                                                      | No                                                                              | Yes (`edit`)                                | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| Edit fields on the Technical tab                                                                                                        | Yes                                                                             | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| **Add Customer**                                                                                                                        | Yes                                                                             | Yes                                         | Yes (creates a customer of Zephyr)                    | Yes                 | Yes (creates a customer of the simulated organization)                     |
| **Edit**, **Merge**, **Change type**, **Create Bulletin**, add a facility or office, and edit facilities or contacts on Customer Detail | Yes                                                                             | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| Change a customer's **Account Owner**                                                                                                   | No                                                                              | Yes (`admin panel`)                         | Per own permissions                                   | Per own permissions | Per the simulated user's permissions                                       |
| Invite, remove, and manage Customer Portal users                                                                                        | Yes                                                                             | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| Upload and browse documents                                                                                                             | Yes                                                                             | Yes                                         | Yes                                                   | Yes                 | Yes                                                                        |
| Products, Visit Planning, and Analytics pages                                                                                           | Depends on whether the feature is available for your organization               | Same                                        | Same                                                  | Same                | Depends on whether the feature is available for the simulated organization |

### Notes

* Permission keys are matched without regard to upper or lower case, and a missing or empty permission list means none of these actions are available.
* `delete` means "can archive." Signal does not have a hard-delete action for assets.
* `promote` covers moving an asset from draft to active, and restoring an archived asset back to active.
* `admin panel` is the only permission Signal calls "admin" on the organization side, and today it only controls changing a customer's Account Owner.
* Signing in and running asset actions also requires that your account has Signal product access, separate from these permission keys. If you have the right permission but still cannot act on an asset, ask your administrator whether your account has Signal access.
