Skip to content

Role Permissions Reference

A user reports that a contract is greyed out, or that they can see an agreement but can’t edit it. Almost always the cause is one of two things: the role they were assigned, or the access condition attached to that role’s permission. This page is the reference for both.

Pactly ships with ten built-in roles. Each role grants a set of permissions, and each permission carries a condition that decides which records it applies to. Understanding the conditions matters as much as the roles, because a permission like “edit a contract” behaves differently depending on whether it is scoped to the whole company or only to records the user owns.

Every permission in Pactly is scoped by one of four conditions. The condition is the reason two people with the same role, or even the same person on two different contracts, can have different abilities.

ConditionWhat it means
Company-wideApplies to every record in the company. The user can act on anything.
Owner onlyApplies only to records the user owns (where they are the assigned contract owner).
UnassignedApplies only to records that have no owner yet.
GroupApplies only to records in a group the user belongs to. Sensitive groups hide their contracts from everyone outside the group, including administrators.

This scoping explains the single most common “why can’t this user act?” case. A plain User can find and view contracts across the whole company, but can only edit, finalize, or manage the ones they own. Seeing a contract is not the same as being able to change it. If a User needs to act on someone else’s contract, reassign the owner or give them a role with company-wide scope.

RoleBest forContract scope
AdminAccount owners, legal ops leadsCompany-wide, plus full account control
ManagerTeam leads who oversee a group’s workCompany-wide (or group-scoped if assigned to groups)
User ManagerDelegated people-adminsNone, manages users only
UserDay-to-day contract ownersView company-wide, act on owned only
LiteOccasional contract ownersSame as User, without the Word add-in and a few extras
RequesterBusiness users raising intake requestsTheir own requests only
ApproverReviewers who sign off on requestsTheir own requests, plus approve/reject
ViewerRead-only stakeholdersRead-only across company data
ReportsAnalysts and financeDashboards and exports only
Contract Manager (legacy)Wide read access to contracts. Hidden by default and not offered to new companies; only present on accounts where it was already set upCompany-wide contract visibility

The tables below list the default permission for each role and resource. Values mean:

  • Yes: granted, company-wide
  • Owner: granted, but only for records the user owns
  • Group: granted, but only within the user’s groups
  • No: not granted
ActionAdminManagerUser MgrUserLiteRequesterApproverViewerReportsContract Mgr
Manage company settingsYesNoNoNoNoNoNoNoNoNo
Configure SSO and integrationsYesNoNoNoNoNoNoNoNoNo
Manage usersYesNoYesNoNoNoNoNoNoNo
Assign rolesYesNoYesNoNoNoNoNoNoNo
Manage groupsYesYesNoNoNoNoNoNoNoNo
View user listYesYesYesNoNoNoNoNoNoNo
ActionAdminManagerUser MgrUserLiteRequesterApproverViewerReportsContract Mgr
Find and view contractsYesYesNoYesYesNoNoYesNoYes
Create a contractYesYesNoYesYesNoNoNoNoNo
Edit a contractYesYesNoOwnerOwnerNoNoNoNoNo
Finalize, archive, terminateYesYesNoOwnerOwnerNoNoNoNoNo
Request approvalYesYesNoOwnerOwnerNoNoNoNoNo
Approve or rejectYesYesNoNoNoNoYesNoNoNo
Request signatureYesYesNoOwnerOwnerNoNoNoNoNo
Delete a contractYesNoNoNoNoNoNoNoNoNo
ActionAdminManagerUser MgrUserLiteRequesterApproverViewerReportsContract Mgr
Raise a contract requestYesYesNoYesYesYesYesNoNoNo
View own requestsYesYesNoYesYesOwnerOwnerNoNoNo
Use templatesYesYesNoYesYesNoNoYesNoYes
Run a playbook reviewYesYesNoOwnerOwnerNoNoNoNoNo
View dashboards and analyticsYesYesNoNoNoNoNoNoYesNo
Run data exportsYesYesNoNoNoNoNoNoYesNo
Use the Word add-inYesYesNoYesNoNoNoNoNoNo

When a Manager is assigned to one or more groups, their company-wide contract visibility narrows to those groups. A Manager with no groups sees everything; a Manager with groups sees only their groups’ contracts.

Sensitive groups go further: contracts in a sensitive group are hidden from everyone who is not a member, including administrators. If an Admin reports they cannot see a contract that clearly exists, check whether it sits in a sensitive group they have not been added to. For how groups work, see Using Groups for Document Access.

The permissions above are the built-in defaults. An administrator can layer changes on top of any built-in role: add a permission, remove one, or rename the role so it matches your organization’s language (for example, showing Manager as “Faculty Admin”). The role key Pactly uses underneath stays the same, so a renamed role keeps its inheritance and behavior.

Because of this, the matrix on this page is the starting point, not a guarantee of how your account is configured. To audit your live setup, open the role editor and review the permissions on each role.

Chat with us

We typically reply within a few minutes