Skip to main content
Two things determine what someone can do in Adopt: which clients they can access (scoping) and what role they hold (permissions). Both apply together.

Access scoping comes first

No matter their role, a person only sees the clients (workstreams) they’ve been granted. A powerful role on a client they can’t access still shows them nothing. Access is granted per workstream — see Access scoping.

Typical roles

Screenshot 2026 07 27 At 12 16 37 PM
Exact role names vary by org and plan; the common shape is:
  • Reviewer / End user — runs tasks and reviews/approves output for the clients they’re on. The core finance-professional role.
  • Builder — sets up agents: connectors, data, instructions, skills, scheduling. Configures the clients they build for.
  • Admin — manages members, roles, billing, and org-wide settings. Broadest reach.
  • Specialized platform roles — some orgs have finer roles (for example, platform-admin or skill-publisher roles) for platform-level administration and publishing skills.
Confirm the exact role list and their precise capabilities in your org’s admin settings — roles can be extended per plan.

Roles at the review gate

Reviewers for the human-in-the-loop gate are set at the engagement level. Within a single client, the R&D reviewer and the transfer-pricing reviewer can be different people. This lets review responsibility follow expertise.
Least privilege. Give people the narrowest role and the fewest clients that let them do their job. It keeps the isolation guarantees meaningful and limits the blast radius if an account is ever compromised.

Next steps

  1. Access scoping
  2. Isolation and multi-tenancy
  3. Managing members