Access in Brainis resolves from two layers, and the stricter one always wins.
Layer one: organization role
| Role | Meaning |
|---|---|
| Owner | Everything, including billing and deleting the organization |
| Admin | Manage settings, members, and all modules |
| Member | Normal user; module access granted per module |
| Guest | Limited external collaborator |
Owners and admins bypass module-level checks. Keep the number of admins small for exactly that reason.
Layer two: per-module level
Within each OS, a person is a viewer (read), member (do their own work), manager (act across the team), or admin (configure the module). This is where real access control happens for most people.
A salesperson might be manager in Revenue, member in Work, viewer in People, and have no access to Finance.
Invite presets
Presets set sensible module levels for common roles in one click: Plain Employee, Account Executive, Sales Manager, RevOps, Recruiter, Hiring Manager, TA Lead, and others. Adjust afterward as needed.
Permission walls
When someone (or an AI) is refused an action, the refusal is logged with its reason and appears in Admin under permission walls. This is genuinely useful: a pattern of refusals usually means someone's access is wrong, not that someone is misbehaving.
Tip: Audit module levels quarterly and after every reorganization. Access accumulates; people change roles and keep old permissions, which is the most common way sensitive data becomes over-shared.
