Roles and what they may do
Every person in your company has one role in your Atlas. Roles belong to your company; the same person can hold a different role in another company that runs Atlas, whatever world it runs.
| Can | Owner | Admin | Operator | Viewer |
|---|---|---|---|---|
| Read every screen, finance included | yes | yes | yes | yes |
| Acknowledge alerts, enter evidence, update records | yes | yes | yes | no |
| Export reports | yes | yes | yes | yes |
| Change finance assumptions, covenant, cash-floor and reserve policy | yes | no | no | no |
| Invite people, change roles, disable accounts, end sessions | yes | yes | no | no |
| Branding, preferences, integrations | yes | yes | no | no |
| Send, pay or execute outside Atlas | held | held | held | no |
A viewer is read-only, finance included. Inviting someone as a viewer is a decision to show them the company; it is not a reduced view.
Some things no role in your company can do on its own: promote or remove an owner, change your company's address, delete the instance, or reset an owner's authenticator. Those go through Titan support with your owner's authorisation, and each leaves a receipt.
Held means Atlas prepares the action and a person decides. Nothing leaves Atlas — no email, no payment, no instruction to a third party — without a named person choosing it.