Role-Based Access Control (RBAC)
Align your team structure with your data governance strategy.
Role-Based Access Control enables organizations to manage user permissions across projects and environments. The system restricts feature access based on assigned user roles, supporting data governance requirements.
Roles
Freshpaint provides five user roles with distinct permission levels.
Admin: Full administrative access including user management, project/environment creation, and HIPAA allowlist configuration.
Data Manager: Elevated data access with the ability to view and modify PHI allowlists, and configure consent management settings.
General User: Standard operational access for configuring destinations and events. General users have PHI visibility, but no ability to modify allowlists or consent settings.
Event Manager: Focused access for managing event tracking and integrations without access to PHI or form submissions.
Data Viewer: Read-only access limited to viewing analytics dashboards and reports.
User Permissions by Role
PHI Access
β
β
β
β
β
Allowlist (modify)
β
β
β
β
β
Destinations
β
β
β
β
β
Event Library
β
β
β
β
β
Audiences (view)
β
β
β
β
β
Audiences (edit)
β
β
β
β
β
Forms (beta)
β
β
β
β
β
Consent Management (view)
β
β
β
β
β
Consent Management (edit)
β
β
β
β
β
Analytics
β
β
β
β
β
Audit Log
β
β
β
β
β
Web Tracker Monitoring
β
β
β
β
β
Video
β
β
β
β
β
Offline Attributions
β
β
β
β
β
Live View
β
β
β
β
β
Visual Editor
β
β
β
β
β
Access to Projects and Environments
Users can see the environments they have access to in the left navigation panel in Freshpaint. Admins always have access to all environments, and can grant access to specific environments to specific users.
When a new environment is created, all users have access by default. An admin must explicitly restrict access via the Teams page.
Granting Environment Access
To invite new users:
Navigate to Settings β Team Members
Click Add Teammate
Enter the user's email address
Select their role from the list
If non-Admin, select the projects and environments they can access
Click Send Invite

The invite link expires after one week. Users should check their spam folder if they don't see the email.
To grant access to existing users,
Navigate to Settings β Team Members
Select the user to configure
Under Environment Access, select the projects and environments
Click Save

Access to Freshpaint Audiences
RBAC for AudiencesLast updated
Was this helpful?