# People and roles: who may do what

Permissions in draften sit on three levels: the organisation, the mailbox and
the installation. Organisation roles are set on the people, mailbox roles on the
mailbox itself.

## Roles in the organisation

Set them in **Organisation → People and roles**.

| Role | May do |
|---|---|
| owner | everything a manager may, plus make and remove other owners. **Has owner rights on every mailbox** |
| manager | invite people, add and connect mailboxes, manage model keys, CRM connections and outgoing mail, and read the change history. **Has editor rights on every mailbox** |
| member | sees only the mailboxes they were given access to, with the role they have there |

The last owner of an organisation stays — they cannot be removed. Removing
someone from the organisation also takes away their access to mailboxes.

> Most people in a company are **members**. Give the manager role only to
someone who really sets up mailboxes and access.

## Roles on a mailbox

The mailbox owner sets them in **Settings → Mailbox and access**, under
**Access to the mailbox**. The organisation's owners and managers always have
access; everyone else by the role you give them here.

| Role | May do |
|---|---|
| read only | look at drafts, mail, activity. Changes nothing |
| editor | the same, plus change settings, instructions and knowledge, and decide in Learning |
| owner | the same, plus manage the mailbox's assistants, their name and signature, the mailbox's keys and access; may connect a CRM of their own for this mailbox only |

The user help is written for the **editor**: it covers working with drafts,
instructions, knowledge and learning.

## The operator of the installation

Above the organisations there is one more level: the **operator**, the person
who runs the installation. They see **Installation**: the organisations,
invitations to found one, the default model keys and mail sender, and the
Operations page. **They see nothing inside an organisation:** they set it up
or send an invitation to found it, seat an owner, suspend it or delete it;
the owners run the rest.

For the cloud service the operator is draften; on your own installation it is
your administrator. More in [Installation](/en/admin/installation-admin).

## What roles cannot do

- **A role does not change the safety net.** Not even an owner can let the
  assistant send or delete mail — draften has no such access to the mailbox.
  See [The safety net](/en/admin/safety-net).
- **A role is not access to the mailbox.** For the assistant to see the mail,
  the mailbox has to be connected; that is separate, see
  [Connecting a mailbox](/en/admin/adding-a-mailbox).

## Who changed what

Every change of a role, an instruction or a setting is written into the
**change history**: who, what, from what to what and when. The record cannot be
edited or deleted.

## Inviting someone

1. Open **Organisation → People and roles**.
2. Click **Invite** and enter an e-mail address.
3. Pick the role in the organisation. Access to a particular mailbox is added
   separately.
4. The invitation is sent from the address the organisation has set as its
   outgoing mail. If the organisation has none of its own, it comes from the
   operator of the installation. **Never from the assistant's mailbox.**

The link for setting a password is valid for **7 days**. Anyone who signs in to
draften with a Microsoft or Google account needs no password link at all — the
invitation only tells them where to sign in.

!> Sending an invitation again **invalidates the old link** and starts the
period over. If someone still has the old invitation open, tell them to use the
new one.
