> ## Documentation Index
> Fetch the complete documentation index at: https://docs.experio.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & Permissions

> Who does what in an implementation, and which admin permissions each person needs

## The implementation team

| Role | Side | Responsibilities | Time commitment |
| - | - | - | - |
| **Forward Facing Engineer (FFE)** | Experio | Leads the implementation and is Experio's project lead. Facilitates the modeling workshops, enters and tunes the configuration, runs pilot ingestion and scoring, and trains the super user. Brings in Experio SMEs as needed. Merges WS1 outputs into `questions.md` with the super user. | Most of the engagement |
| **Experio SMEs** | Experio | Specialists the FFE brings in for specific areas, for example data modeling, integrations and connectors, agents and flows, or security and access control. Join the workshops in their area and help with the configuration. | As needed |
| **Project Manager (PM)** | Client | Plan, calendar, decision log, status reports, risks. Books the client's people for each workshop. Scribe and timekeeper in workshops. | Part-time throughout |
| **Executive sponsor** | Client | Sets goals and success criteria, chooses use cases, resolves escalations, signs off go-live. | Kickoff, phase reviews |
| **Super user** | Client | Owns the decisions with the experts. Reviews the configuration between workshops, works the review queues during the pilot, scores golden questions with the FFE, and owns the configuration after handover. | 25–50% during the engagement |
| **Subject-matter experts (SMEs)** | Client | One or more per use case. Bring the real questions, the documents and the business rules. Validate answers. | Their workshops plus scoring |
| **Data owners** | Client | Owners of HR, CRM and finance systems. Provide exports or API access, and explain columns and keys. | WS2, WS6 |
| **IT / storage admin** | Client | Creates connector OAuth apps and service accounts, grants folder access, sets up SSO. | Phase 0, WS2 |
| **Legal / compliance** | Client | Access-control rules, sensitive data and ethical walls. | WS2, WS9 |
| **Pilot users** | Client | 5–10 per use case. Do the acceptance testing. | Phase 5 |

## Who decides what

| Decision | Recommends | Decides | Consulted |
| - | - | - | - |
| Use cases and success criteria | FFE | Sponsor | Super user |
| Golden questions and expected answers | SMEs | Super user | FFE |
| Entity types and relationships | FFE | Super user | SMEs |
| Taxonomy source and ownership | Super user | Data owner | FFE |
| Artifact types and extraction depth | FFE | Super user | SMEs |
| Match keys and review thresholds | FFE | Super user | Data owners |
| Access-control policy | FFE | Legal / compliance | Super user, IT |
| Go-live | PM and FFE | Sponsor | Everyone |

## Admin permission groups

Admin access uses six permission groups. Each group grants **read** (see the pages) or **write** (change them). Items a user can't read are hidden from the sidebar.

| Group | Controls |
| - | - |
| **Graph Managers** | Ontology, Compatibility, Artifact Types, Taxonomies, Client Configuration, Access Control (read and checks) |
| **Data Source Managers** | Connectors, Data Sources, Data Mapping, scans, Graph Evaluation, AI helpers on Artifact Types and Data Mapping |
| **Process Managers** | Matching Strategies, Conflict Resolution, Enrichment Rules |
| **AI Managers** | Agent Configuration (assistants), Model Configurations, MCP Servers, Personas, AI Instructions, Copilot settings |
| **Monitoring Managers** | Startup Health, Scaling, Logs |
| **User Administrators** | Users, Usage Statistics, Disclosure, SSO Configuration |

Some pages need more than a group:

* **Agent Flows** and **Document Templates** require a **staff** account to create and edit.
* **Access-control policy** rows are edited in the staff admin. Some Access Control diagnostics require a superuser.

## Recommended bundles

| Person | Recommended access |
| - | - |
| FFE | Superuser during the implementation |
| Experio SMEs | Superuser, or write access on the groups for their area, during the implementation |
| Client super user | **Write:** Graph, Data Source, Process, AI. **Read:** Monitoring. **Staff** if they will build agent flows or document templates. |
| Conflict-queue reviewers | **Write:** Process. **Read:** Graph. |
| Data owners | **Read:** Data Source, to see mapping and job results |
| IT admin | **Write:** Data Source (connectors), User Administrators (SSO) |
| End users | No admin groups |

<Tip>
  Give reviewers and SMEs read access to **Model & Define** early. Reviewing the ontology and artifact types in the product between workshops is much faster than reviewing screenshots.
</Tip>

<Warning>
  Keep superuser and access-control policy editing with Experio until handover, unless the client's legal team owns ethical walls and has been trained on the policy model.
</Warning>

## Setting permissions

Group roles are assigned in the staff admin (`/staff/`). Open the user, and add a row per group under **Group Permissions**, with read or write. The same page sets **staff** status under **Admin Options**. Only superusers can do this, so the FFE sets up the client's accounts during Phase 0.

If the client uses SSO, configure it first on **Administer > SSO Configuration**, so that accounts exist before workshops start. See [SSO Configuration](/admin-guide/sso-configuration).
