Skip to main content
Role-based access control (RBAC) is a foundational security model in the Thena platform that ensures users have appropriate access based on their responsibilities and organizational hierarchy. This system protects sensitive operations while enabling efficient collaboration.
The Thena platform implements a progressive access model with five distinct user roles, each designed for specific use cases and access requirements

User roles and permissions

The Thena platform provides five user roles, each with specific access levels and capabilities. Use the tabs below to explore each role in detail:
  • Org admin
  • Org user
  • Lite user
  • Customer admin
  • Customer user
Organization administrators have comprehensive access to manage their organizationโ€™s resources, settings, and members. This is the highest level of access within an organization.
  • Create and delete teams
  • Add and remove team members
  • Update team configurations
  • Manage routing rules
  • Configure team settings
  • Set up team hierarchies
  • Manage ticket priorities, statuses, and types
  • Configure custom fields and objects
  • Set up tags and categories
  • Manage forms and templates
  • Configure organization settings
  • Control workflow automation
  • Send organization invitations
  • Manage user access and permissions
  • Configure notification channels
  • Oversee bulk operations
  • Control user role assignments
  • Manage user onboarding/offboarding
  • View subscription details
  • Create and manage subscriptions
  • Access billing portal
  • Monitor usage and costs
  • Manage payment methods
  • Control subscription features

Role comparison matrix

The following table shows which features are available to each role:
FeatureOrg adminOrg userLite userCustomer adminCustomer user
Ticket Management
Create ticketsโœ…โœ…โŒโŒโœ…
View all ticketsโœ…โœ…โœ…โŒโŒ
View assigned ticketsโœ…โœ…โœ…โŒโœ…
Update ticket statusโœ…โœ…โŒโŒโœ…
Assign ticketsโœ…โœ…โŒโŒโŒ
Delete ticketsโœ…โŒโŒโŒโŒ
Escalate ticketsโœ…โœ…โŒโŒโŒ
Account Management
Create accountsโœ…โœ…โŒโŒโŒ
View accountsโœ…โœ…โœ…โŒโŒ
Update accountsโœ…โœ…โŒโŒโŒ
Manage customer contactsโœ…โœ…โŒโŒโŒ
Add account notesโœ…โœ…โŒโŒโŒ
Team Management
Create teamsโœ…โŒโŒโŒโŒ
View teamsโœ…โœ…โœ…โŒโŒ
Add team membersโœ…โŒโŒโŒโŒ
Configure team settingsโœ…โŒโŒโŒโŒ
Manage routing rulesโœ…โŒโŒโŒโŒ
System Configuration
Manage ticket typesโœ…โŒโŒโŒโŒ
Configure custom fieldsโœ…โŒโŒโŒโŒ
Set up tagsโœ…โŒโŒโŒโŒ
Manage formsโœ…โŒโŒโŒโŒ
User Management
Send invitationsโœ…โŒโŒโœ…โŒ
Manage user permissionsโœ…โŒโŒโœ…โŒ
Configure notificationsโœ…โŒโŒโœ…โŒ
Personal Settings
Update profileโœ…โœ…โœ…โœ…โœ…
Configure preferencesโœ…โœ…โœ…โœ…โœ…
Set availabilityโœ…โœ…โŒโŒโŒ
Customer Portal
Access customer portalโŒโŒโŒโœ…โœ…
Configure portal settingsโŒโŒโŒโœ…โŒ
Use help centerโŒโŒโŒโœ…โœ…
Billing & Subscriptions
View billingโœ…โŒโŒโŒโŒ
Manage subscriptionsโœ…โŒโŒโŒโŒ
Access billing portalโœ…โŒโŒโŒโŒ

Common access scenarios

Here are typical scenarios for role assignment and user access management:
  • New team member
  • Lite user access
  • Administrative promotion
  • Customer onboarding
Scenario: A new employee joins your organization and needs access to the platform for daily work.
1

User registration

New employee creates an account or receives an invitation to join the organization
2

Role assignment

Organization admin assigns the org user role, providing complete operational access
3

Team assignment

Admin adds the user to relevant teams, granting team-specific access and permissions
4

Ready to work

User can now manage tickets, accounts, and collaborate with team members effectively
Most new team members should start with the org user role as it provides the right balance of access for daily operations without administrative privileges.
โŒ˜I