In brief: Beamy attaches permissions to roles, never to people. Four standard roles ship with the platform, and you can create as many more as your organisation needs. A user carries one role, and only one.
The principle: permissions live on the role
Beamy applies role-based access control, or RBAC. You do not grant rights to Marie and Karim, you define a "Security manager" role and you assign it to them.
Three practical consequences:
Onboarding and offboarding take one gesture. You change the role, not a list of rights.
A policy change happens in one place. Editing the role updates everyone who carries it, at once.
Auditing becomes readable. "Who can edit an authorization?" is answered by reading the roles, not by walking through the accounts.
Where to find it
The configuration menu opens from the navigation bar header, next to your organisation's name. Inside Settings, the Roles and permissions block holds two spaces:
Roles: the definition of the roles and their permissions.
Users: the accounts, their role and their platform access.
ℹ️ Reaching either space requires the Settings permission. Without it, the entry does not appear in the menu.
The 3 standard roles
Role | What it opens |
User | Read only. View applications, view Guidance campaigns, view catalog feedbacks and promotions. This is the role granted by default. |
Super User | Everything User does, plus: edit application data, edit their authorization, export the Apps module, manage segments, manage automations, full access to Guidance, to Complementary Sources and to workflows. |
Admin | Full access to the whole platform, Settings included: roles, users, Web Browser Extension, integrations. |
⚠️ A standard role cannot be edited nor deleted. For a need that fits none of the four, create a custom role.
The role granted by default
Anyone connecting for the first time, SSO included, receives the User role. It grants read access, never write. You change it afterwards from the Users space.
ℹ️ The View applications permission is granted automatically to every role, including the ones you create. The platform does not work without it: it opens read access to the Apps module, the Product Sheets, the dashboards, the alerts and the tasks, navigation through the workflows and commenting in the activity feed.
