ATLAS.

Roles and what they may do

Every person in your company has one role in your Atlas. Roles belong to your company; the same person can hold a different role in another company that runs Atlas, whatever world it runs.

CanOwnerAdminOperatorViewer
Read every screen, finance includedyesyesyesyes
Acknowledge alerts, enter evidence, update recordsyesyesyesno
Export reportsyesyesyesyes
Change finance assumptions, covenant, cash-floor and reserve policyyesnonono
Invite people, change roles, disable accounts, end sessionsyesyesnono
Branding, preferences, integrationsyesyesnono
Send, pay or execute outside Atlasheldheldheldno

A viewer is read-only, finance included. Inviting someone as a viewer is a decision to show them the company; it is not a reduced view.

Some things no role in your company can do on its own: promote or remove an owner, change your company's address, delete the instance, or reset an owner's authenticator. Those go through Titan support with your owner's authorisation, and each leaves a receipt.

Held means Atlas prepares the action and a person decides. Nothing leaves Atlas — no email, no payment, no instruction to a third party — without a named person choosing it.