Skip to main content
Orgo Permissions is the role-based access control system within Orgo that governs which features and data users can access, based on permission domain (ADMIN, HR, FINANCIAL, EVENT, COMMUNICATION) and scope level (organization, regional, or local). Built for organizations that delegate admin work across chapters, regions, or committees, including professional associations, alumni networks, trade unions, and faith communities that need different people to manage different areas at different levels of the organization. Replaces shared admin logins and informal trust-based access for routine, ongoing responsibilities, not for one-off exceptions, where direct permission assignment to a single user profile is still the documented approach. Unlike organizational roles, permissions directly grant access to features and data.
Looking for how to create positions like “President” or “Secretary”? See Roles for organizational structure.

Permission Domains Overview

Orgo has 6 permission domains, each controlling a specific area of the platform:
ADMIN is the highest permission - users with ADMIN have access to everything, including all other domains.

Domain Comparison

What Can Each Permission Do?

This table shows which features each permission domain controls:

Detailed Domain Descriptions

Who needs it: Executive team, IT administrators, platform managersWhat it controls:
  • All organization settings and configuration
  • Billing, subscription, and payment gateway setup
  • Feature flags and module activation
  • API access and integrations
  • User permission assignment
  • Local center creation and settings
Important: ADMIN permission grants access to everything. Users with ADMIN can do anything that HR, FINANCIAL, EVENT, or COMMUNICATION can do.
Be careful assigning ADMIN. These users have access to all organization data, financial information, and can modify any settings.
Who needs it: HR staff, membership officers, secretariesWhat it controls:
  • View and edit member profiles
  • Process membership adhesions (applications)
  • Handle member resignations
  • Import members in bulk
  • Manage badges and gamification
  • Access Official Gazette
  • Export member data
  • View birth dates and personal information
Includes: HR permission automatically includes HR_ASSISTANT capabilities.
Who needs it: Volunteers helping with membership, identity validatorsWhat it controls:
  • Identity document validation
  • GDPR data requests processing
  • Gamification and training hours tracking
  • View (not edit) member information
Note: This is a lighter permission for users who need to help with specific HR tasks without full member management access.
Who needs it: Treasurers, finance officers, accountantsWhat it controls:
  • Create and manage products
  • Configure membership fees
  • Process payments and refunds
  • View financial reports and statistics
  • Manage Stripe integration
  • Export financial data
Includes: FINANCIAL permission automatically includes HR_ASSISTANT capabilities (for viewing member info related to payments).
Who needs it: Event coordinators, activity managersWhat it controls:
  • Create and edit events
  • Manage event attendees
  • Check-in participants (QR scanning)
  • Generate event reports
  • Manage courses and training sessions
  • Configure event ticketing
Does NOT include: Financial event settings (ticket pricing) require FINANCIAL permission.
Who needs it: Communications officers, community managersWhat it controls:
  • Create and send newsletters
  • Moderate discussion forums
  • Manage discussion categories
  • Pin/delete discussion posts
  • Send announcements

Permission Hierarchy

Permissions have a hierarchy where higher permissions include lower ones:

Automatic Inclusions

Example: A user with HR permission can also validate identities and manage gamification (HR_ASSISTANT features) without needing a separate assignment.

Scope Levels (TENANT / PARENT_LOCAL / LOCAL)

Each permission domain can be assigned at different scope levels that control what data the user can access:

How it works

The same permission at different scopes gives access to the same features, but limited to different data:
Key principle: _TENANT permission automatically covers all _PARENT_LOCAL and _LOCAL data within that domain.

Visual Example


Complete Permission Reference

All Available Permissions

Level indicates permission strength. Higher level permissions can assign lower level permissions to other users.

Assigning and auditing

Recommended assignments, how to grant permissions, how to test them with impersonation, and how to see who currently holds what are all in Assigning Permissions.