> ## Documentation Index
> Fetch the complete documentation index at: https://help.palletlog.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> Understand how workspace access controls sensitive Palletlog actions while exact role names are verified.

Roles limit sensitive actions such as partner administration, exports, corrections, and billing.

Exact role names and the full permission matrix are **not verified** yet. Do not invent role titles beyond what your workspace already shows.

<Note>
  Interface labels, screenshots, and step-by-step UI guidance in this article are pending verification against the live Palletlog application. Conceptual guidance below uses approved Palletlog terminology. Detailed UI steps will be added when product sources are confirmed.
</Note>

## Outcome

You understand why an action may be blocked and who can grant access.

## Capability areas that are usually restricted

Until Product publishes an official matrix, treat these as areas that often require elevated access:

| Capability area                    | Why it matters                              |
| ---------------------------------- | ------------------------------------------- |
| Team and workspace administration  | Adding/removing people and changing access  |
| Partner and network administration | Invites, access, and shared balances        |
| Movement corrections               | Changing recorded quantities after the fact |
| Exports and reports                | Taking data out of the workspace            |
| Billing and subscription           | Plan and payment changes                    |
| Security settings                  | Authentication and account protection       |

If one of these actions is blocked for you, ask a **workspace administrator** before contacting support.

## Practical guidance

* Prefer least privilege: grant only the access needed for daily tasks.
* Keep at least two administrators when possible so access is not locked to one person.
* When inviting **Team members**, assign the narrowest role your workspace offers for their job.
* Re-check access after role changes with a test login when the change is high impact.

<Note>
  If you do not have permission to complete an action in Palletlog, ask a workspace administrator to adjust your role or complete the task for you.
</Note>

## Related articles

* [Team members](/account/team-members)
* [Account security](/account/account-security)
* [Manage partner access](/partners/manage-access)
* [Billing and subscription](/account/billing)
