Permissions Matrix
This is every permission in Two Minute Reports — 71 of them, in 12 groups — and which of the six standard roles holds each one.
A tick means the role includes the permission. Where the Seat column says Yes, the member also needs an assigned seat: their role permits it, but nothing happens until a seat is assigned. See Seats for what that means in practice.
Connections
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View connections | See which platforms are connected and whether each is still authorised. Never exposes credentials or tokens. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Add and edit connections | Authorise a new platform, or re-authorise one that has expired. A connection is shared: once added, the whole team can build on it. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Remove connections | Disconnects the platform. Every dashboard, sheet and schedule drawing on it stops returning data. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| View connected accounts | See the ad accounts, properties and profiles available under each connection. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Enable accounts | Makes an account available for reporting. Every connector has its own account limit on your plan, so enabling can hit that limit — and raising it costs money. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Disable accounts | Frees a slot against that connector's account limit. Reports already using the account stop returning data. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Send data setup links | Email a client a link that lets them connect their own accounts. They need no seat and never enter your team. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
Clients
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View clients | See the client list and which accounts belong to each. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Add and edit clients | Create a client, rename one, or change its branding. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Remove clients | Deletes the client. Dashboards and goals attached to it are unlinked, not deleted. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| View account mapping | See which connected accounts are assigned to which client. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Map accounts to clients | Assign or reassign a connected account to a client. This decides what every client-scoped report contains. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Unmap accounts | Removes the assignment. Reports scoped to that client lose the account's data. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
Dashboards
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View dashboards | Open any dashboard in the team and see its data, including running the queries it already contains. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit dashboards | Build a dashboard, add or change widgets, change the layout. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete dashboards | Permanent, and for everyone in the team. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View themes | See the team's saved themes. Applying one to a dashboard is part of editing that dashboard. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit themes | Change the agency's brand colours, fonts and logos. Editing a theme restyles every dashboard already using it. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Delete themes | Dashboards using the theme fall back to the default. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| View share links | See which dashboards have been published outside the team, and to whom. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Share dashboards externally | Create a link that shows a dashboard to someone with no account in your team. This publishes data outside the team. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Revoke share links | Anyone holding the link loses access immediately. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View briefings | See scheduled dashboard emails, their recipients and their send history. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit briefings | Set up a scheduled email of a dashboard: recipients, cadence and content. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete briefings | Stops all future sends and removes the send history. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Queue a briefing | Puts a briefing in line to go out. If the team requires approval it waits for someone who can send; if not, it goes. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Approve or reject a briefing | Release a held briefing to its recipients, or send it back with a reason. Only members whose role includes this can be chosen as a team's briefing approvers — the picker in team settings disables everyone else and says why. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Send briefings to clients | Release a briefing to its recipients yourself, outside the approval flow. Where approval is switched on, releasing a held briefing is 'Approve or reject a briefing' instead — and nobody may release their own briefing, whatever their role. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
Goals
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View goals | See targets and pacing for any client or account. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit goals | Set a target, the period it covers and what it measures. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete goals | Removes the goal and its recorded history. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
Initiatives
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View initiatives | See the log of work done for clients and what each change moved. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit initiatives | Record a change made for a client, and close or archive one. Initiatives are never deleted. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
Custom Fields
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View custom fields | See the team's calculated metrics and dimensions and how each is defined. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit custom fields | Define a calculated metric or dimension. Editing one changes every dashboard, sheet and goal that uses it — which is why this sits above Editor. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
| Delete custom fields | Anything still referencing the field stops calculating. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
Google Sheets
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View sheet reports | See the team's Google Sheets reports and what each one pulls. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit sheet reports | Create a new sheet report or change an existing one. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete sheet reports | Removes the report from TMR along with its queries and schedules. The Google Sheet itself is not touched. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View sheet queries | See the accounts, metrics, dimensions and date ranges behind each sheet. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit sheet queries | Change what a sheet pulls — accounts, metrics, dimensions, filters, date range. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Run queries | Refresh a sheet on demand, or run a query while building one. Each run calls the ad platform and costs us money, which is why it needs a seat even though viewing the same query does not. Scheduled refreshes are not affected — they run on the team's plan, with no person attached. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete sheet queries | Removes the query and any refresh schedule attached to it. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View refresh schedules | See when each sheet refreshes and whether the last run succeeded. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit refresh schedules | Set how often a sheet refreshes automatically. Schedules count towards your plan's schedule limit, and the shortest frequency you may choose depends on the plan. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete refresh schedules | The sheet stops refreshing on its own. Manual refresh still works. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
Google Data Studio
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View Studio data sources | See the query configuration behind each Looker Studio data source. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit Studio data sources | Change what a Looker Studio data source pulls. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Delete Studio data sources | Looker Studio reports built on it stop returning data. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
MCP & API Access
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| Connect AI clients over MCP | Lets this member's AI clients reach the team. What they can do once connected is exactly this member's permissions — never more. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Use the public API | Lets this member's API keys work against the team. A key carries the member's permissions and its scopes can only narrow them, never widen them. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Query data over MCP and the API | Build a query in the request — your choice of accounts, metrics, dimensions and date range — and get the rows back, without going through a saved report. Applies to those two channels only: in the Hub and in Google Sheets, building a dashboard or a sheet report is covered by that resource's own write permission. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
AI Features
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| Use Dash | Ask the AI assistant about the team's data. Dash can only reach what the member operating it can reach — it holds no permissions of its own. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Generate dashboards with AI | Have a dashboard built from a description. Free today; this may become a metered feature. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View Watch Tower | See what Watch Tower has flagged across clients. Not yet released. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Configure Watch Tower | Act on what Watch Tower flags — re-run a check, mark a finding resolved, record feedback. Acting on a finding still needs the permission for that action: re-sending a failed briefing needs 'Send briefings to clients'. Configuring the rules is a separate permission. Not yet released. | Yes | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View Watch Tower rules | See the rules that decide what Watch Tower flags, and which clients each one applies to. Not yet released. | — | ✓ | ✓ | ✓ | ✓ | — | — |
| Create and edit Watch Tower rules | Mute a signal, change its severity, or set a threshold — for one client or the whole team. A rule changes what everyone in the team is shown, which is why it sits above the permission to act on a finding. Not yet released. | Yes | ✓ | ✓ | ✓ | ✓ | — | — |
Team & Roles
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View team members | See who is in the team, the role each holds and who occupies a seat. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Invite members | Send an invitation. You can only offer a role whose permissions you hold yourself. | Yes | ✓ | ✓ | ✓ | — | — | — |
| Remove members | Only possible where the other member's permissions are contained in yours. The Owner can never be removed. | Yes | ✓ | ✓ | ✓ | — | — | — |
| Change member roles | Bounded in both directions: you cannot grant a permission you lack, and you cannot change someone who holds one you lack. | Yes | ✓ | ✓ | ✓ | — | — | — |
| Assign and remove seats | Decide who can change things, without changing anyone's role. A seat is a switch, not a capability — no role, standard or custom, can grant itself one. | Yes | ✓ | ✓ | ✓ | — | — | — |
| View roles | See the standard roles and any custom roles the team has built, and exactly what each one includes — including the role you hold yourself. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit custom roles | Build a role from individual permissions. You can only include permissions you hold yourself — without that limit this is a superuser button. Restricted to Admin and Owner. | Yes | ✓ | ✓ | — | — | — | — |
| View team settings | See the team name, defaults and whether briefings require approval. | — | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Change team settings | Rename the team, set defaults, and decide whether briefings need approval before reaching clients. | Yes | ✓ | ✓ | ✓ | — | — | — |
| View the audit log | See who did what and when — role changes, removals, external shares, plan changes. Not yet released. | — | ✓ | ✓ | ✓ | — | — | — |
Plan & Billing
| Permission | What it does | Seat | Owner | Admin | Deputy | Data Mgr | Editor | Viewer |
|---|---|---|---|---|---|---|---|---|
| View usage against plan limits | See how much of the plan is used — enabled accounts per connector, Google Sheets schedules, and seats. Not what any of it costs. Whoever can consume a limit can see it. | — | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View the plan and invoices | See which plan the team is on, what it costs, the payment method on file, and past invoices. | — | ✓ | ✓ | ✓ | — | — | — |
| Change the plan and pay | Upgrade, downgrade, buy seats and add-ons, change payment details, and cancel the subscription. The one permission that can end the contract. | Yes | ✓ | ✓ | — | — | — | — |
Totals
| Role | Permissions | What it is for |
|---|---|---|
| Owner | 71 of 71 | The person who pays. Holds every permission, cannot be removed or re-roled by anyone, and can change the plan and assign seats with or without a seat of their own. |
| Admin | 71 of 71 | Every permission, including changing the plan and cancelling the subscription. |
| Deputy Admin | 70 of 71 | Runs the team — invites people, sets roles, assigns seats, changes settings. Cannot change the plan or end the contract. |
| Data Manager | 62 of 71 | Sets the data up: connections, connected accounts, clients, account mapping, custom fields and brand themes. No team administration. |
| Editor | 46 of 71 | Builds reports on data someone else set up. Cannot add a connection, map an account, or define a custom field. |
| Viewer | 22 of 71 | Reads everything the team has. Changes nothing. |
46 of the 71 permissions require a seat. The other 25 are reads, plus API and MCP access — a member with no seat can still see everything their role allows, and any integration they set up keeps running.
The Six Standard Roles
Owner, Admin, Deputy Admin, Data Manager, Editor and Viewer — what each role is for, what it cannot do, and how to choose between them.
Seats
A seat is permission to change things in one team. What a seatless member can still do on every surface, what is refused, and why scheduled refreshes never stop.