Two Minute Reports Logo
Roles & Permissions

Permissions Matrix

Every permission in Two Minute Reports and which of the six standard roles holds it, including which permissions require a seat.

This is every permission in Two Minute Reports — 73 of them, in 13 groups — and which of the six standard roles holds each one.

A tick means the role includes the permission. Where the Seat column says Yes, the member also needs an assigned seat: their role permits it, but nothing happens until a seat is assigned. See Seats for what that means in practice.

Reading this to work out why someone cannot do something? Check the Seat column first. A role that includes the permission plus a member with no seat is the most common answer, and adding a seat fixes it without changing anyone's role.

Connections

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View connectionsSee which platforms are connected and whether each is still authorised. Never exposes credentials or tokens.—✓✓✓✓✓✓
Add and edit connectionsAuthorise a new platform, or re-authorise one that has expired. A connection is shared: once added, the whole team can build on it.Yes✓✓✓✓——
Remove connectionsDisconnects the platform. Every dashboard, sheet and schedule drawing on it stops returning data.Yes✓✓✓✓——
View connected accountsSee the ad accounts, properties and profiles available under each connection.—✓✓✓✓✓✓
Enable accountsMakes an account available for reporting. Every connector has its own account limit on your plan, so enabling can hit that limit — and raising it costs money.Yes✓✓✓✓——
Disable accountsFrees a slot against that connector's account limit. Reports already using the account stop returning data.Yes✓✓✓✓——
Send data setup linksEmail a client a link that lets them connect their own accounts. They need no seat and never enter your team.Yes✓✓✓✓——

Clients

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View clientsSee the client list and which accounts belong to each.—✓✓✓✓✓✓
Add and edit clientsCreate a client, rename one, or change its branding.Yes✓✓✓———
Remove clientsDeletes the client. Dashboards and goals attached to it are unlinked, not deleted.Yes✓✓✓———
View account mappingSee which connected accounts are assigned to which client.—✓✓✓✓✓✓
Map accounts to clientsAssign or reassign a connected account to a client. This decides what every client-scoped report contains.Yes✓✓✓✓——
Unmap accountsRemoves the assignment. Reports scoped to that client lose the account's data.Yes✓✓✓✓——

Dashboards

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View dashboardsOpen any dashboard in the team and see its data, including running the queries it already contains.—✓✓✓✓✓✓
Create and edit dashboardsBuild a dashboard, add or change widgets, change the layout.Yes✓✓✓✓✓—
Delete dashboardsPermanent, and for everyone in the team.Yes✓✓✓✓✓—
View themesSee the team's saved themes. Applying one to a dashboard is part of editing that dashboard.—✓✓✓✓✓✓
Create and edit themesChange the agency's brand colours, fonts and logos. Editing a theme restyles every dashboard already using it.Yes✓✓✓✓——
Delete themesDashboards using the theme fall back to the default.Yes✓✓✓✓——
View share linksSee which dashboards have been published outside the team, and to whom.—✓✓✓✓✓✓
Share dashboards externallyCreate a link that shows a dashboard to someone with no account in your team. This publishes data outside the team.Yes✓✓✓✓✓—
Revoke share linksAnyone holding the link loses access immediately.Yes✓✓✓✓✓—
View briefingsSee scheduled dashboard emails, their recipients and their send history.—✓✓✓✓✓✓
Create and edit briefingsSet up a scheduled email of a dashboard: recipients, cadence and content.Yes✓✓✓✓✓—
Delete briefingsStops all future sends and removes the send history.Yes✓✓✓✓✓—
Queue a briefingPuts a briefing in line to go out. If the team requires approval it waits for someone who can send; if not, it goes.Yes✓✓✓✓✓—
Approve or reject a briefingRelease a held briefing to its recipients, or send it back with a reason. Only members whose role includes this can be chosen as a team's briefing approvers — the picker in team settings disables everyone else and says why.Yes✓✓✓✓✓—
Send briefings to clientsRelease a briefing to its recipients yourself, outside the approval flow. Where approval is switched on, releasing a held briefing is 'Approve or reject a briefing' instead — and nobody may release their own briefing, whatever their role.Yes✓✓✓✓——

Goals

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View goalsSee targets and pacing for any client or account.—✓✓✓✓✓✓
Create and edit goalsSet a target, the period it covers and what it measures.Yes✓✓✓✓✓—
Delete goalsRemoves the goal and its recorded history.Yes✓✓✓✓✓—

Initiatives

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View initiativesSee the log of work done for clients and what each change moved.—✓✓✓✓✓✓
Create and edit initiativesRecord a change made for a client, and close or archive one. Initiatives are never deleted.Yes✓✓✓✓✓—

Custom Fields

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View custom fieldsSee the team's calculated metrics and dimensions and how each is defined.—✓✓✓✓✓✓
Create and edit custom fieldsDefine a calculated metric or dimension. Editing one changes every dashboard, sheet and goal that uses it — which is why this sits above Editor.Yes✓✓✓✓——
Delete custom fieldsAnything still referencing the field stops calculating.Yes✓✓✓✓——

Google Sheets

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View sheet reportsSee the team's Google Sheets reports and what each one pulls.—✓✓✓✓✓✓
Create and edit sheet reportsCreate a new sheet report or change an existing one.Yes✓✓✓✓✓—
Delete sheet reportsRemoves the report from TMR along with its queries and schedules. The Google Sheet itself is not touched.Yes✓✓✓✓✓—
View sheet queriesSee the accounts, metrics, dimensions and date ranges behind each sheet.—✓✓✓✓✓✓
Create and edit sheet queriesChange what a sheet pulls — accounts, metrics, dimensions, filters, date range.Yes✓✓✓✓✓—
Run queriesRefresh a sheet on demand, or run a query while building one. Each run calls the ad platform and costs us money, which is why it needs a seat even though viewing the same query does not. Scheduled refreshes are not affected — they run on the team's plan, with no person attached.Yes✓✓✓✓✓—
Delete sheet queriesRemoves the query and any refresh schedule attached to it.Yes✓✓✓✓✓—
View refresh schedulesSee when each sheet refreshes and whether the last run succeeded.—✓✓✓✓✓✓
Create and edit refresh schedulesSet how often a sheet refreshes automatically. Schedules count towards your plan's schedule limit, and the shortest frequency you may choose depends on the plan.Yes✓✓✓✓✓—
Delete refresh schedulesThe sheet stops refreshing on its own. Manual refresh still works.Yes✓✓✓✓✓—

Google Data Studio

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View Studio data sourcesSee the query configuration behind each Looker Studio data source.—✓✓✓✓✓✓
Create and edit Studio data sourcesChange what a Looker Studio data source pulls.Yes✓✓✓✓✓—
Delete Studio data sourcesLooker Studio reports built on it stop returning data.Yes✓✓✓✓✓—

MCP & API Access

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
Connect AI clients over MCPLets this member's AI clients reach the team. What they can do once connected is exactly this member's permissions — never more.—✓✓✓✓✓✓
Use the public APILets this member's API keys work against the team. A key carries the member's permissions and its scopes can only narrow them, never widen them.—✓✓✓✓✓✓
Query data over MCP and the APIBuild a query in the request — your choice of accounts, metrics, dimensions and date range — and get the rows back, without going through a saved report. Applies to those two channels only: in the Hub and in Google Sheets, building a dashboard or a sheet report is covered by that resource's own write permission.Yes✓✓✓✓✓—

AI Features

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
Use DashAsk the AI assistant about the team's data. Dash can only reach what the member operating it can reach — it holds no permissions of its own.Yes✓✓✓✓✓✓
Generate dashboards with AIHave a dashboard built from a description. Free today; this may become a metered feature.Yes✓✓✓✓✓—
View Watch TowerSee what Watch Tower has flagged across clients. Not yet released.—✓✓✓✓✓✓
Configure Watch TowerAct on what Watch Tower flags — re-run a check, mark a finding resolved, record feedback. Acting on a finding still needs the permission for that action: re-sending a failed briefing needs 'Send briefings to clients'. Configuring the rules is a separate permission. Not yet released.Yes✓✓✓✓✓—
View Watch Tower rulesSee the rules that decide what Watch Tower flags, and which clients each one applies to. Not yet released.—✓✓✓✓——
Create and edit Watch Tower rulesMute a signal, change its severity, or set a threshold — for one client or the whole team. A rule changes what everyone in the team is shown, which is why it sits above the permission to act on a finding. Not yet released.Yes✓✓✓✓——

Team & Roles

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View team membersSee who is in the team, the role each holds and who occupies a seat.—✓✓✓✓✓✓
Invite membersSend an invitation. You can only offer a role whose permissions you hold yourself.Yes✓✓✓———
Remove membersOnly possible where the other member's permissions are contained in yours. The Owner can never be removed.Yes✓✓✓———
Change member rolesBounded in both directions: you cannot grant a permission you lack, and you cannot change someone who holds one you lack.Yes✓✓✓———
Assign and remove seatsDecide who can change things, without changing anyone's role. A seat is a switch, not a capability — no role, standard or custom, can grant itself one.Yes✓✓✓———
View rolesSee the standard roles and any custom roles the team has built, and exactly what each one includes — including the role you hold yourself.—✓✓✓✓✓✓
Create and edit custom rolesBuild a role from individual permissions. You can only include permissions you hold yourself — without that limit this is a superuser button. Restricted to Admin and Owner, and cannot be included in a custom role — see Custom Roles.Yes✓✓————
View team settingsSee the team name, defaults and whether briefings require approval.—✓✓✓✓✓✓
Change team settingsRename the team, set defaults, and decide whether briefings need approval before reaching clients.Yes✓✓✓———
View the audit logSee who did what and when — role changes, removals, external shares, plan changes. Not yet released.—✓✓✓———

Plan & Billing

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View usage against plan limitsSee how much of the plan is used — enabled accounts per connector, Google Sheets schedules, and seats. Not what any of it costs. Whoever can consume a limit can see it.—✓✓✓✓✓—
View the plan and invoicesSee which plan the team is on, what it costs, the payment method on file, and past invoices.—✓✓✓———
Change the plan and payUpgrade, downgrade, buy seats and add-ons, change payment details, and cancel the subscription. The one permission that can end the contract.Yes✓✓————

Custom Domains

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
See the custom domainSee which domain client-facing report and setup links are served from, and whether it is currently working.—✓✓✓———
Change the custom domainPoint a domain the agency owns at client-facing links, or remove one. Removing a live domain breaks every branded link already sent to a client — the reports themselves stay reachable at their original addresses, but the link in the client's inbox stops resolving.Yes✓✓————

Totals

RolePermissionsWhat it is for
Owner73 of 73The person the subscription belongs to. Has the same permissions as an Admin, but cannot be removed or given another role by anyone, and can manage billing and assign seats even without a seat of their own.
Admin73 of 73Everything a Deputy Admin can do, plus the three nobody else has: managing billing — changing the plan, payment details, cancelling — creating custom roles, and setting the custom domain client links are served from.
Deputy Admin70 of 73Everything a Data Manager can do, plus runs the team: creates and deletes clients, invites people, sets roles, assigns seats, changes team settings, and reads the audit log and the plan. Can't change the plan, create roles, or set a custom domain.
Data Manager60 of 73Everything an Editor can do, plus owns the data everyone builds on: connections, connected accounts, which accounts belong to which client, custom fields and brand themes. Can't create or delete clients, and no team administration.
Editor46 of 73Everything a Viewer can do, plus builds the work: dashboards, briefings, goals, sheet queries and schedules. Can't add connections, map clients, or create custom fields.
Viewer22 of 73Can see everything the team has and change none of it. A good fit for clients and stakeholders.

47 of the 73 permissions require a seat. The other 26 are reads, plus API and MCP access — a member with no seat can still see everything their role allows, and any integration they set up keeps running.

Copyright © 2026