Skip to main content
Nexalytica uses a layered role system to give the right people the right level of control without exposing sensitive data or settings to those who don’t need them. Roles exist at two distinct levels — Organisation and Department — and a separate set of sharing levels governs what recipients can do with a specific resource. Understanding how these layers interact lets you delegate confidently and collaborate safely.

Organisation Roles

Organisation roles apply across your entire Nexalytica Organisation. Every member of your Organisation holds exactly one organisation role.
The Org Owner is the person who originally created the Organisation. This role is permanent — it cannot be transferred, removed, or demoted. The Owner holds every capability that an Org Admin holds, plus absolute control over the Organisation itself.
Org Admins manage the Organisation day-to-day. Assign this role to people who need to onboard new members, restructure Departments, oversee billing, or review resources across the Organisation using the audited Admin View. You can have multiple Org Admins.Key powers an Org Admin has that no other role holds:
  • Invite and remove Organisation members
  • Manage Departments
  • Manage billing and subscription settings
  • Use the Admin View to access any member’s resources (every use is logged)
Every new person who joins your Organisation starts as a Member. Members create and own resources within the Departments they belong to. They have no Organisation-level admin powers — they cannot invite others, manage billing, or see colleagues’ private resources.
“Member” is the Organisation-level catch-all term. A Member also holds a Department role (Dept Admin, Manager, or Employee) that governs what they can do inside a specific Department.

Department Roles

Department roles apply within a single Department. A person can hold different Department roles in different Departments simultaneously. Department roles never grant Organisation-level powers.

Dept Admin

Full control over one Department’s members and resources — add or remove members, edit Department settings, manage all resources scoped to that Department. Cannot access private resources of colleagues or perform any org-level actions.

Manager

Creates and owns resources; handles most everyday operational work inside the Department. Cannot manage Department membership (adding/removing people). Cannot view colleagues’ private resources.

Employee

The base working role. Creates and owns resources within the Department. No management authority over other members or Department settings.
The order of authority within a Department is: Dept Admin > Manager > Employee. Across the Organisation as a whole, the order is: Org Owner > Org Admin > (Dept Admin / Manager / Employee).

Sharing Levels

When you share a resource with someone, you assign them one of three sharing levels. These levels are independent of the person’s Organisation or Department role.
External recipients — people outside your Organisation who receive a shared link — are always Viewers. They cannot re-share the resource under any circumstances, regardless of what level you attempt to grant them.

The Cap-at-Own-Level Rule

You can never grant someone more access than you yourself hold. If you are an Editor on a resource, you can share it with others as a Viewer or Editor — but you cannot elevate anyone to Owner. Only the resource Owner can grant Owner-level access. This rule applies at every level of sharing:
  • An Editor sharing with a colleague → max grant is Editor
  • A Viewer cannot re-share at all
  • An Owner sharing with anyone → can grant up to Owner
If you need to give a colleague Owner-level control over a resource you only have Editor access to, ask the current Owner to transfer ownership or to share directly at the Owner level.

Capability Matrix

The table below shows which actions each role can perform. “Yes” means the role always has this capability; “Dept Admin only” means only that specific Department role qualifies.
Roles are additive and the highest role always wins. If you hold both a Manager role in one Department and a Dept Admin role in another, each role applies independently within its own Department. Your Organisation role always takes precedence over any Department role for Organisation-level actions.

Key Rules to Remember

Highest role wins

When a person holds multiple roles, their effective permissions are the union of all roles they hold. The strongest applicable role governs each action.

Admin View is audited

Only Org Owners and Org Admins can activate the Admin View. Every activation is logged in the Audit Log — there is no silent or untracked access to colleagues’ private resources.

Dept roles are scoped

A Dept Admin’s power stops at their Department’s boundary. They cannot manage other Departments, and they cannot see private resources even within their own Department.

External = Viewer only

Anyone outside your Organisation who receives a shared link is locked to Viewer access and cannot re-share the resource with others.