Operator Roles & Capabilities

What each Operator Portal role can do, and what every capability unlocks

Every operator in the Operator Portal has one role. A role is a bundle of capabilities, and each capability unlocks a specific screen, button, or action. This article shows every role, what it can do, and what each capability means.

You pick an operator's role when you add or edit an operator. If an operator is assigned to more than one directory, they can have a different role in each one.

Roles at a glance

RoleBuilt forIn short
Account OwnerThe person who owns the partner relationshipEverything an Admin can do, plus directory settings, directory billing details, removing accounts, and transferring ownership. There is one Account Owner per directory.
AdminPortal administratorsEverything a System Manager can do, plus managing other Admins, logging in as operators, Secure accounts, features, packages, content, and external subscriptions.
System ManagerTeam leads and operationsFull client-account management, plan changes, and creating and editing operators. Cannot manage Admins.
SupportSupport agentsWorks on client accounts (log in, reset passwords, edit details, view history). No subscription or billing actions.
Support External BillingSupport agents who handle partner-billed plansSupport + subscription management for external subscriptions.
Support InTandem BillingSupport agents who handle platform-billed plansSupport + subscription management for InTandem subscriptions.
Support All BillingSenior support / billing specialistsSupport + subscription management for all subscription types, including free.
Web ConsultantWeb developersHelps accounts with setup and widget implementation. Can lock accounts.
DesignerDesignersBranding work, tags, notes, and setting accounts as templates.
Campaign ManagerMarketing team membersMarketing work such as tags and notes, identities, templates, and history.
SalesOnboarding / sales repsHelps new accounts during setup only. Cannot log in to accounts after setup is complete.
Content ManagerContent editorsOnly manages content (identities and library). No access to client accounts.
📘

Secure roles

System Manager, Support, Web Consultant, Designer, and Campaign Manager each have a Secure version (for example, Support Secure). A Secure role has exactly the same capabilities as its regular version, plus one more: it can log in to accounts marked as Secure. Account Owners and Admins can always log in to Secure accounts.

Use Secure accounts and Secure roles for clients with strict privacy requirements, such as HIPAA.

How the roles build on each other

Most roles are layered, so you can think of them as steps up a ladder:

  • Support is the base for customer-facing work.
  • Support billing roles = Support + subscription management (see Billing support roles).
  • System Manager = full client-account management + creating and editing regular operators.
  • Admin = System Manager + managing Admins, logging in as operators, Secure accounts, features, packages, content, integrations, and external subscriptions.
  • Account Owner = Admin + directory settings, directory billing details, removing accounts, and transferring ownership.

Web Consultant, Designer, Campaign Manager, Sales, and Content Manager are specialist roles. Each one has a narrow set of capabilities for a specific job.

Billing support roles

The Operator Portal handles two kinds of subscriptions:

  • External subscriptions: You bill the client yourself, outside the platform. The subscription records what the client has, but the platform doesn't charge them.
  • InTandem subscriptions: The platform bills the client (monthly, annual, or one-time charges).

Free subscriptions can only be handled by an operator who can manage both external and InTandem subscriptions.

RoleExternalInTandemFree
Account Owner
Admin
Support External Billing
Support InTandem Billing
Support All Billing
Support

System Managers can view subscriptions, change and cancel plans, and manage staff seats, but they can't add external or InTandem subscriptions.

🚧

Note

The billing support roles are only offered when the new Subscription Management experience is enabled for your directory.

Who can assign which role

  • Any operator who can create or edit operators can assign System Manager, Support, the billing support roles, Web Consultant, Designer, Campaign Manager, Sales, and all Secure roles.
  • Only an Admin or the Account Owner can make someone an Admin.
  • Content Manager is only offered when the content manager is enabled for your directory.
  • Account Owner can't be assigned from the operator form. The current Account Owner transfers ownership with Set As Owner in the Operators list.
  • Platform Admin is an internal role reserved for the inTandem team. It isn't available to partner operators.

Capability matrix

Columns: Owner = Account Owner, Sys Mgr = System Manager, Sup Ext / Sup InT / Sup All = Support External / InTandem / All Billing, Web Cons = Web Consultant, Campaign = Campaign Manager, Content = Content Manager.

Secure roles aren't shown as separate columns. Each one matches its regular role, plus Log in as a Secure account.

Client account access

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
View client accounts
Log in as an account
Log in as an account in setup
Log in as a Secure account

Client account details

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
Edit notes
Edit tags
View history
View Integration tab
View identities
Assign identities
Assign operators
Mark setup as complete
Set as template
Edit nickname
Reset password
Change account owner

Client account controls

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
Create accounts
Lock account
Enable send links
Mark account as Secure
Unblock campaigns
Remove accounts

Integrations

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
Edit campaign keyword
Yext import
Soci settings

Subscriptions & billing

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
New Subscription tab
View & manage subscriptions
Change plan
Cancel subscription
Manage staff seats
External subscriptions
InTandem subscriptions

Operators

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
View operators
Create operators
Edit operators
Edit Admins
Block operators
Block Admins
Delete operators
Log in as an operator
Transfer ownership

Directory & portal settings

CapabilityOwnerAdminSys MgrSupportSup ExtSup InTSup AllWeb ConsDesignerCampaignSalesContent
Directory settings
Directory billing details
Contact Us
Manage features
View packages
Manage packages
Content manager
Map identity professions

What each capability means

Client account access

  • View client accounts (business:read): Shows Client Accounts in the menu and lets the operator open the account list and account pages.
  • Log in as an account (business:impersonate): Enables Login As on a client account, and on individual staff members in the Staff tab.
  • Log in as an account in setup (business:impersonate_in_setup): Enables Login As only while the account is still in setup. This is how the Sales role helps new accounts get started.
  • Log in as a Secure account (business:impersonate_secure): Required to log in to accounts marked as Secure. Regular login access isn't enough for Secure accounts.

Client account details

  • Edit notes (business:edit_note): Edit the account Note in the business information panel.
  • Edit tags (business:edit_tags): Add and remove account Tags.
  • View history (business:history): Shows the History tab and subscription history, so you can see what your team changed on the account.
  • View Integration tab (business:view_integration): Shows the account's Integration tab.
  • View identities (business:view_assign_identities): Shows the account's Identities on the Account tab (read-only).
  • Assign identities (business:assign_identities): Edit the account's Identities.
  • Assign operators (business:assign_operators): Edit Operator assignments to divide accounts among your team.
  • Mark setup as complete (business:setup_completed): Shows Mark setup as complete for accounts that are still in setup.
  • Set as template (business:set_as_template): Mark an account as a template for creating new accounts with the same settings.
  • Edit nickname (business:update_nickname): Edit the account Nickname, which is used in the Business Page URL and as an external business ID.
  • Reset password (business:change_password): Set a new password for the account's primary admin.
  • Change account owner (business:change_account_owner): Choose which staff member is the account's owner.

Client account controls

  • Create accounts (business:create): Shows New Client Account, to create an account from scratch or from a template.
  • Lock account (business:lock_business): Lock or unlock the account. A locked account blocks everyone from logging in, including the owner, staff, and operators.
  • Enable send links (business:forbid_link): Let a new account send external links before its 30-day screening period ends.
  • Mark account as Secure (business:set_store_pii): Turn the Secure setting on or off. Only operators with a Secure role, an Admin, or the Account Owner can log in to Secure accounts.
  • Unblock campaigns (business:unblock_promotional): Unblock an account's promotional campaigns from the Integration tab.
  • Remove accounts (business:remove_account): Select accounts in the Client Accounts list and remove them from your directory.

Integrations

  • Edit campaign keyword (business:change_campaign_keyword): Edit the Campaign keyword on the Integration tab.
  • Yext import (business:import_yext): Use the Yext actions on the Integration tab (import, reinitiate, and open Yext).
  • Soci settings (business:update_soci): Edit and update the account's Soci settings on the Integration tab.

Subscriptions & billing

  • New Subscription tab (business:subscription_management_v2): Shows the new Subscription tab, with the plan overview and subscription history.
  • View & manage subscriptions (business:manage_subscriptions): Shows the account's subscriptions list, with Add subscription and actions on each subscription. This is the base capability for all subscription work.
  • Change plan (business:change_plan): Shows Change plan, to move the account to a different plan or extend a trial.
  • Cancel subscription (business:cancel_plan): Shows Cancel subscription.
  • Manage staff seats (business:manage_staff_seat_subscriptions): Add staff seats to an account as subscriptions.
  • External subscriptions (business:manage_external_subscriptions): Add and manage subscriptions you bill outside the platform.
  • InTandem subscriptions (business:manage_intandem_subscriptions): Add and manage subscriptions the platform bills for. An operator with both this and External subscriptions can also manage free subscriptions.

Operators

  • View operators (operator:read): Shows Operators in the menu and the list of operators.
  • Create operators (operator:create): Shows New Operator.
  • Edit operators (operator:update): Edit an operator's details, role, and directory assignments.
  • Edit Admins (operator:update_admin): Also required to edit an operator who is an Admin or the Account Owner.
  • Block operators (operator:lock_operator): Block or Unblock an operator. You can't block yourself or the Account Owner.
  • Block Admins (operator:lock_admin): Also required to block or unblock an Admin.
  • Delete operators (operator:soft_delete_operator): Delete an operator.
  • Log in as an operator (operator:impersonate): Use Login as on another operator to see the portal the way they do.
  • Transfer ownership (operator:set_owner): Use Set As Owner to make another operator the directory's Account Owner.

Directory & portal settings

  • Directory settings (directory:update): Open and save Directory settings from the profile menu.
  • Directory billing details (directory:billing): View the directory's billing email and invite link in Directory settings.
  • Contact Us (directory:contact_us): Shows Contact Us in the menu.
  • Manage features (feature:manage): Shows Manage Features, to view, create, and edit features.
  • View packages (package:read): Shows Manage Packages in view-only mode.
  • Manage packages (package:manage): Create, clone, and edit packages.
  • Content manager (content:manage): Shows the content manager menu (identities and library).
  • Map identity professions (content:map_identities_professions): Map professions to identities in the content manager.

Capabilities that depend on your directory's setup

Some capabilities only work when the related feature is turned on for your directory. If the feature is off, operators won't see the screen or button, even if their role includes it. This applies to:

  • The Integration tab, and the Yext, Soci, and campaign keyword actions
  • Change plan, Cancel subscription, staff seats, and the new Subscription tab
  • Identities
  • Removing accounts
  • Manage Features, Manage Packages, and the content manager
  • Directory billing details

To turn one of these on, contact your inTandem account manager.


Did this page help you?