Role Permissions Reference
A user reports that a contract is greyed out, or that they can see an agreement but can’t edit it. Almost always the cause is one of two things: the role they were assigned, or the access condition attached to that role’s permission. This page is the reference for both.
Pactly ships with ten built-in roles. Each role grants a set of permissions, and each permission carries a condition that decides which records it applies to. Understanding the conditions matters as much as the roles, because a permission like “edit a contract” behaves differently depending on whether it is scoped to the whole company or only to records the user owns.
The four access conditions
Section titled “The four access conditions”Every permission in Pactly is scoped by one of four conditions. The condition is the reason two people with the same role, or even the same person on two different contracts, can have different abilities.
| Condition | What it means |
|---|---|
| Company-wide | Applies to every record in the company. The user can act on anything. |
| Owner only | Applies only to records the user owns (where they are the assigned contract owner). |
| Unassigned | Applies only to records that have no owner yet. |
| Group | Applies only to records in a group the user belongs to. Sensitive groups hide their contracts from everyone outside the group, including administrators. |
This scoping explains the single most common “why can’t this user act?” case. A plain User can find and view contracts across the whole company, but can only edit, finalize, or manage the ones they own. Seeing a contract is not the same as being able to change it. If a User needs to act on someone else’s contract, reassign the owner or give them a role with company-wide scope.
The ten roles at a glance
Section titled “The ten roles at a glance”| Role | Best for | Contract scope |
|---|---|---|
| Admin | Account owners, legal ops leads | Company-wide, plus full account control |
| Manager | Team leads who oversee a group’s work | Company-wide (or group-scoped if assigned to groups) |
| User Manager | Delegated people-admins | None, manages users only |
| User | Day-to-day contract owners | View company-wide, act on owned only |
| Lite | Occasional contract owners | Same as User, without the Word add-in and a few extras |
| Requester | Business users raising intake requests | Their own requests only |
| Approver | Reviewers who sign off on requests | Their own requests, plus approve/reject |
| Viewer | Read-only stakeholders | Read-only across company data |
| Reports | Analysts and finance | Dashboards and exports only |
| Contract Manager (legacy) | Wide read access to contracts. Hidden by default and not offered to new companies; only present on accounts where it was already set up | Company-wide contract visibility |
What each role can do
Section titled “What each role can do”The tables below list the default permission for each role and resource. Values mean:
- Yes: granted, company-wide
- Owner: granted, but only for records the user owns
- Group: granted, but only within the user’s groups
- No: not granted
Account and access management
Section titled “Account and access management”| Action | Admin | Manager | User Mgr | User | Lite | Requester | Approver | Viewer | Reports | Contract Mgr |
|---|---|---|---|---|---|---|---|---|---|---|
| Manage company settings | Yes | No | No | No | No | No | No | No | No | No |
| Configure SSO and integrations | Yes | No | No | No | No | No | No | No | No | No |
| Manage users | Yes | No | Yes | No | No | No | No | No | No | No |
| Assign roles | Yes | No | Yes | No | No | No | No | No | No | No |
| Manage groups | Yes | Yes | No | No | No | No | No | No | No | No |
| View user list | Yes | Yes | Yes | No | No | No | No | No | No | No |
Contracts
Section titled “Contracts”| Action | Admin | Manager | User Mgr | User | Lite | Requester | Approver | Viewer | Reports | Contract Mgr |
|---|---|---|---|---|---|---|---|---|---|---|
| Find and view contracts | Yes | Yes | No | Yes | Yes | No | No | Yes | No | Yes |
| Create a contract | Yes | Yes | No | Yes | Yes | No | No | No | No | No |
| Edit a contract | Yes | Yes | No | Owner | Owner | No | No | No | No | No |
| Finalize, archive, terminate | Yes | Yes | No | Owner | Owner | No | No | No | No | No |
| Request approval | Yes | Yes | No | Owner | Owner | No | No | No | No | No |
| Approve or reject | Yes | Yes | No | No | No | No | Yes | No | No | No |
| Request signature | Yes | Yes | No | Owner | Owner | No | No | No | No | No |
| Delete a contract | Yes | No | No | No | No | No | No | No | No | No |
Requests, templates, and analytics
Section titled “Requests, templates, and analytics”| Action | Admin | Manager | User Mgr | User | Lite | Requester | Approver | Viewer | Reports | Contract Mgr |
|---|---|---|---|---|---|---|---|---|---|---|
| Raise a contract request | Yes | Yes | No | Yes | Yes | Yes | Yes | No | No | No |
| View own requests | Yes | Yes | No | Yes | Yes | Owner | Owner | No | No | No |
| Use templates | Yes | Yes | No | Yes | Yes | No | No | Yes | No | Yes |
| Run a playbook review | Yes | Yes | No | Owner | Owner | No | No | No | No | No |
| View dashboards and analytics | Yes | Yes | No | No | No | No | No | No | Yes | No |
| Run data exports | Yes | Yes | No | No | No | No | No | No | Yes | No |
| Use the Word add-in | Yes | Yes | No | Yes | No | No | No | No | No | No |
Group scope and sensitive groups
Section titled “Group scope and sensitive groups”When a Manager is assigned to one or more groups, their company-wide contract visibility narrows to those groups. A Manager with no groups sees everything; a Manager with groups sees only their groups’ contracts.
Sensitive groups go further: contracts in a sensitive group are hidden from everyone who is not a member, including administrators. If an Admin reports they cannot see a contract that clearly exists, check whether it sits in a sensitive group they have not been added to. For how groups work, see Using Groups for Document Access.
Customizing roles
Section titled “Customizing roles”The permissions above are the built-in defaults. An administrator can layer changes on top of any built-in role: add a permission, remove one, or rename the role so it matches your organization’s language (for example, showing Manager as “Faculty Admin”). The role key Pactly uses underneath stays the same, so a renamed role keeps its inheritance and behavior.
Because of this, the matrix on this page is the starting point, not a guarantee of how your account is configured. To audit your live setup, open the role editor and review the permissions on each role.
Related
Section titled “Related”Chat with us
We typically reply within a few minutes