Two Minute Reports Logo
Roles & Permissions

The Six Standard Roles

Owner, Admin, Deputy Admin, Data Manager, Editor and Viewer — what each role is for, what it cannot do, and how to choose between them.

Every team comes with six roles. They are not six levels of seniority — they are six different jobs, and the two in the middle exist because setting data up and building reports on it are usually done by different people.

At a Glance

RoleBest forCannot
OwnerThe person who pays— nothing is withheld
AdminA co-owner who runs the account with you— nothing is withheld
Deputy AdminAn operations lead who runs the team day to dayChange the plan or cancel · Create or edit roles
Data ManagerWhoever owns the connections and client setupAnything to do with the team or the plan
EditorReport builders working on data someone else set upAdd a connection, map an account, define a custom field
ViewerClients and stakeholders who only readChange anything at all

Each role includes everything the one below it can do, plus more. So a Data Manager can do everything an Editor can, and an Editor everything a Viewer can. See the permissions matrix for the exact lists.

Owner

The person whose email the subscription is under. The Owner holds every permission and is the one role nobody else can touch: they cannot be removed, cannot be given a different role, and do not need a seat of their own to change the plan or hand out seats.

That last part is deliberate. If the Owner needed a seat to assign seats, a team that ran out of seats could never assign another one.

The Owner follows the account, not the person — it is not a role you hand out. To change who it is, contact [email protected].

Admin

Everything the Owner can do, including changing the plan and cancelling the subscription. The difference is not a permission — an Admin holds exactly the same set — but that an Admin is a role somebody assigned, and can therefore be un-assigned.

Because the two sets are identical, one Admin cannot change or remove another: roles are only editable downwards and equal does not count as below. The account Owner can, and is the only person who can. If you need an Admin removed and you are not the Owner, the Owner has to do it.

Give this to a business partner or a co-founder — someone you would trust to end the contract.

An Admin can cancel the subscription and change the payment method. If that is more than you meant to hand over, Deputy Admin is almost certainly the role you want.

Deputy Admin

Runs the team: invites people, sets their roles, assigns and un-assigns seats, changes team settings, and does everything a Data Manager and Editor can do.

Holds two permissions fewer than Admin. A Deputy Admin cannot change the plan — no buying seats, altering payment details or cancelling — though they can see what the plan is and how much of it is used, so they know when to come and ask. And they cannot create or edit roles, which is what stops somebody building a custom role to give themselves the first one.

This is the right role for an operations manager, a team lead, or whoever actually onboards people.

Data Manager

Owns the setup. Connections, connected accounts, clients, account mapping, custom fields and brand themes — everything that has to exist before anyone can build a report. Plus everything an Editor can do.

No team administration: a Data Manager cannot invite anyone, change a role, or assign a seat.

In an agency this is usually the person who onboards a new client's ad accounts.

Editor

Builds reports on data somebody else set up: dashboards, goals, Google Sheets queries and schedules, Looker Studio query configs, briefings.

An Editor cannot add a connection, enable a connected account, map an account to a client, or define a custom field. That is not a restriction on their competence — it is that those actions have consequences beyond their own work. Enabling an account consumes a plan limit and costs money; removing a connection breaks every report drawing on it.

This is the default role for most people who do the work.

Viewer

Reads everything the team has and changes nothing. Viewers can open dashboards, see clients and reports, and read the queries in a sheet — but every control that would change something is unavailable to them.

Viewers do not see the plan, invoices or billing. They also cannot run a query on demand, because each run calls the ad platform and costs money.

Give this to clients, stakeholders, and anyone whose job is to look.

How to Choose

Two questions get it right almost every time:

  1. Do they set data up, or build on data that is already there? Setting up is Data Manager; building on it is Editor.
  2. Do they need to add and remove people? If yes, Deputy Admin. If they also need to change the plan, Admin.
When you are unsure, pick the smaller role. Widening it later is one dropdown, and nobody minds being given more access. Discovering that a new starter deleted a connection on their second day is a different conversation.

If none of the six fit, build a custom role with exactly the permissions you want.

Roles and Seats Are Separate

Assigning a role does not give someone a seat. A member with the Editor role and no seat sees the whole Hub and can change none of it — every editing control is disabled with an explanation.

That combination is useful on purpose: it is how you give a client's marketing manager full visibility of the reports without paying for them. But if you have given someone a role and they tell you nothing works, check their seat first.

Copyright © 2026