Two Minute Reports Logo
Roles & Permissions

Permissions Matrix

Every permission in Two Minute Reports and which of the six standard roles holds it, including which permissions require a seat.

This is every permission in Two Minute Reports — 71 of them, in 12 groups — and which of the six standard roles holds each one.

A tick means the role includes the permission. Where the Seat column says Yes, the member also needs an assigned seat: their role permits it, but nothing happens until a seat is assigned. See Seats for what that means in practice.

Reading this to work out why someone cannot do something? Check the Seat column first. A role that includes the permission plus a member with no seat is the most common answer, and adding a seat fixes it without changing anyone's role.

Connections

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View connectionsSee which platforms are connected and whether each is still authorised. Never exposes credentials or tokens.
Add and edit connectionsAuthorise a new platform, or re-authorise one that has expired. A connection is shared: once added, the whole team can build on it.Yes
Remove connectionsDisconnects the platform. Every dashboard, sheet and schedule drawing on it stops returning data.Yes
View connected accountsSee the ad accounts, properties and profiles available under each connection.
Enable accountsMakes an account available for reporting. Every connector has its own account limit on your plan, so enabling can hit that limit — and raising it costs money.Yes
Disable accountsFrees a slot against that connector's account limit. Reports already using the account stop returning data.Yes
Send data setup linksEmail a client a link that lets them connect their own accounts. They need no seat and never enter your team.Yes

Clients

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View clientsSee the client list and which accounts belong to each.
Add and edit clientsCreate a client, rename one, or change its branding.Yes
Remove clientsDeletes the client. Dashboards and goals attached to it are unlinked, not deleted.Yes
View account mappingSee which connected accounts are assigned to which client.
Map accounts to clientsAssign or reassign a connected account to a client. This decides what every client-scoped report contains.Yes
Unmap accountsRemoves the assignment. Reports scoped to that client lose the account's data.Yes

Dashboards

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View dashboardsOpen any dashboard in the team and see its data, including running the queries it already contains.
Create and edit dashboardsBuild a dashboard, add or change widgets, change the layout.Yes
Delete dashboardsPermanent, and for everyone in the team.Yes
View themesSee the team's saved themes. Applying one to a dashboard is part of editing that dashboard.
Create and edit themesChange the agency's brand colours, fonts and logos. Editing a theme restyles every dashboard already using it.Yes
Delete themesDashboards using the theme fall back to the default.Yes
View share linksSee which dashboards have been published outside the team, and to whom.
Share dashboards externallyCreate a link that shows a dashboard to someone with no account in your team. This publishes data outside the team.Yes
Revoke share linksAnyone holding the link loses access immediately.Yes
View briefingsSee scheduled dashboard emails, their recipients and their send history.
Create and edit briefingsSet up a scheduled email of a dashboard: recipients, cadence and content.Yes
Delete briefingsStops all future sends and removes the send history.Yes
Queue a briefingPuts a briefing in line to go out. If the team requires approval it waits for someone who can send; if not, it goes.Yes
Approve or reject a briefingRelease a held briefing to its recipients, or send it back with a reason. Only members whose role includes this can be chosen as a team's briefing approvers — the picker in team settings disables everyone else and says why.Yes
Send briefings to clientsRelease a briefing to its recipients yourself, outside the approval flow. Where approval is switched on, releasing a held briefing is 'Approve or reject a briefing' instead — and nobody may release their own briefing, whatever their role.Yes

Goals

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View goalsSee targets and pacing for any client or account.
Create and edit goalsSet a target, the period it covers and what it measures.Yes
Delete goalsRemoves the goal and its recorded history.Yes

Initiatives

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View initiativesSee the log of work done for clients and what each change moved.
Create and edit initiativesRecord a change made for a client, and close or archive one. Initiatives are never deleted.Yes

Custom Fields

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View custom fieldsSee the team's calculated metrics and dimensions and how each is defined.
Create and edit custom fieldsDefine a calculated metric or dimension. Editing one changes every dashboard, sheet and goal that uses it — which is why this sits above Editor.Yes
Delete custom fieldsAnything still referencing the field stops calculating.Yes

Google Sheets

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View sheet reportsSee the team's Google Sheets reports and what each one pulls.
Create and edit sheet reportsCreate a new sheet report or change an existing one.Yes
Delete sheet reportsRemoves the report from TMR along with its queries and schedules. The Google Sheet itself is not touched.Yes
View sheet queriesSee the accounts, metrics, dimensions and date ranges behind each sheet.
Create and edit sheet queriesChange what a sheet pulls — accounts, metrics, dimensions, filters, date range.Yes
Run queriesRefresh a sheet on demand, or run a query while building one. Each run calls the ad platform and costs us money, which is why it needs a seat even though viewing the same query does not. Scheduled refreshes are not affected — they run on the team's plan, with no person attached.Yes
Delete sheet queriesRemoves the query and any refresh schedule attached to it.Yes
View refresh schedulesSee when each sheet refreshes and whether the last run succeeded.
Create and edit refresh schedulesSet how often a sheet refreshes automatically. Schedules count towards your plan's schedule limit, and the shortest frequency you may choose depends on the plan.Yes
Delete refresh schedulesThe sheet stops refreshing on its own. Manual refresh still works.Yes

Google Data Studio

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View Studio data sourcesSee the query configuration behind each Looker Studio data source.
Create and edit Studio data sourcesChange what a Looker Studio data source pulls.Yes
Delete Studio data sourcesLooker Studio reports built on it stop returning data.Yes

MCP & API Access

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
Connect AI clients over MCPLets this member's AI clients reach the team. What they can do once connected is exactly this member's permissions — never more.
Use the public APILets this member's API keys work against the team. A key carries the member's permissions and its scopes can only narrow them, never widen them.
Query data over MCP and the APIBuild a query in the request — your choice of accounts, metrics, dimensions and date range — and get the rows back, without going through a saved report. Applies to those two channels only: in the Hub and in Google Sheets, building a dashboard or a sheet report is covered by that resource's own write permission.Yes

AI Features

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
Use DashAsk the AI assistant about the team's data. Dash can only reach what the member operating it can reach — it holds no permissions of its own.Yes
Generate dashboards with AIHave a dashboard built from a description. Free today; this may become a metered feature.Yes
View Watch TowerSee what Watch Tower has flagged across clients. Not yet released.
Configure Watch TowerAct on what Watch Tower flags — re-run a check, mark a finding resolved, record feedback. Acting on a finding still needs the permission for that action: re-sending a failed briefing needs 'Send briefings to clients'. Configuring the rules is a separate permission. Not yet released.Yes
View Watch Tower rulesSee the rules that decide what Watch Tower flags, and which clients each one applies to. Not yet released.
Create and edit Watch Tower rulesMute a signal, change its severity, or set a threshold — for one client or the whole team. A rule changes what everyone in the team is shown, which is why it sits above the permission to act on a finding. Not yet released.Yes

Team & Roles

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View team membersSee who is in the team, the role each holds and who occupies a seat.
Invite membersSend an invitation. You can only offer a role whose permissions you hold yourself.Yes
Remove membersOnly possible where the other member's permissions are contained in yours. The Owner can never be removed.Yes
Change member rolesBounded in both directions: you cannot grant a permission you lack, and you cannot change someone who holds one you lack.Yes
Assign and remove seatsDecide who can change things, without changing anyone's role. A seat is a switch, not a capability — no role, standard or custom, can grant itself one.Yes
View rolesSee the standard roles and any custom roles the team has built, and exactly what each one includes — including the role you hold yourself.
Create and edit custom rolesBuild a role from individual permissions. You can only include permissions you hold yourself — without that limit this is a superuser button. Restricted to Admin and Owner.Yes
View team settingsSee the team name, defaults and whether briefings require approval.
Change team settingsRename the team, set defaults, and decide whether briefings need approval before reaching clients.Yes
View the audit logSee who did what and when — role changes, removals, external shares, plan changes. Not yet released.

Plan & Billing

PermissionWhat it doesSeatOwnerAdminDeputyData MgrEditorViewer
View usage against plan limitsSee how much of the plan is used — enabled accounts per connector, Google Sheets schedules, and seats. Not what any of it costs. Whoever can consume a limit can see it.
View the plan and invoicesSee which plan the team is on, what it costs, the payment method on file, and past invoices.
Change the plan and payUpgrade, downgrade, buy seats and add-ons, change payment details, and cancel the subscription. The one permission that can end the contract.Yes

Totals

RolePermissionsWhat it is for
Owner71 of 71The person who pays. Holds every permission, cannot be removed or re-roled by anyone, and can change the plan and assign seats with or without a seat of their own.
Admin71 of 71Every permission, including changing the plan and cancelling the subscription.
Deputy Admin70 of 71Runs the team — invites people, sets roles, assigns seats, changes settings. Cannot change the plan or end the contract.
Data Manager62 of 71Sets the data up: connections, connected accounts, clients, account mapping, custom fields and brand themes. No team administration.
Editor46 of 71Builds reports on data someone else set up. Cannot add a connection, map an account, or define a custom field.
Viewer22 of 71Reads everything the team has. Changes nothing.

46 of the 71 permissions require a seat. The other 25 are reads, plus API and MCP access — a member with no seat can still see everything their role allows, and any integration they set up keeps running.

Copyright © 2026