Skip to content

User Permissions

Grail uses role-based access control (RBAC) to manage what users can do within your organization. Every user is assigned a role that determines their permissions.

There are three roles, from most restricted to most powerful:

  • Viewer — The default role. Browse and search the media library.
  • Editor — Everything a Viewer can do, plus organize assets with tags and metadata, share assets and projects, and request processing jobs.
  • Admin — Full control, including user management, agents, and storage sources.
ActionViewerEditorAdmin
Browse and search assets
Stream and preview media
View transcripts
Add comments and reactions
Update own profile
Change own password
Copy asset paths and export selected assets
View projects
Create and edit tags
Create, edit, and organize projects
Add and remove tags on assets
Share assets publicly
Share projects publicly
View storage source context on assets
Manage agents and storage sources
Configure project roots
Trigger indexing, transcription, and proxy jobs
Create new users
Change user roles and status
Delete users

When a new organization is created through the signup page, the first account becomes the organization’s Admin. That admin can invite teammates, manage roles, and send password resets from the Users page.

Admins can manage users from the Users page in the navigation bar.

From this page you can:

  • Create users — set their name, email, password, and role
  • Edit users — change roles or update user details
  • Delete users — remove a user with a confirmation dialog
  • View user status — see who is active, pending, or suspended
  • Track last login — monitor user activity
  • Sort the user list — sort by user, role, status, last login, last session, or created date
  • Send password resets — help users regain access without changing their password directly

Last Session shows the most recent activity Grail has recorded for a user’s session, while Last Login shows the most recent sign-in.