> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wenite.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Users & Permissions

> Managing user access, roles, and the permission model for a client.

## 1. Managing users

Open a client and go to **Users** ("Manage access to this client"). Users are organized into tabs:

| Tab              | Description                                                    |
| ---------------- | -------------------------------------------------------------- |
| **Portal users** | Users with access to the consultant/HR portal.                 |
| **Contacts**     | Invited respondent contacts (no portal access).                |
| **Hub users**    | Only with a CONTINUOUS license — employees with a Hub account. |
| **User groups**  | Reusable groups for bundling access and rules.                 |

### 1.1 Creating or editing a user

When creating a user, you fill in email, first name, last name, language, and **Role**. The available roles:

| Role            | Description                        |
| --------------- | ---------------------------------- |
| **Admin**       | Can add clients and colleagues.    |
| **Viewer**      | The client, with view-only access. |
| **Member**      | Standard access.                   |
| **Super admin** | Wenite administrator access.       |

You can also link the user to groups and assign socio-demographic attributes.

For a colleague working across your practice, you also set **client access** — which clients this user can see at all. This is checked before any feature-level permission: a user with no access to a client won't see it in their Clients list regardless of what their Role or feature permissions allow elsewhere.

<Tip>
  **Viewer** is the right default for a client contact (e.g. an HR manager) — they get to see their own results without being able to change survey setup or add other users. Reserve **Admin** for people who should be able to add clients and colleagues, and **Member** for colleagues doing day-to-day work who don't need admin rights.
</Tip>

<Note>
  When **Auto-sync users** is enabled, the buttons to manually add or import users are hidden — users then come from the external source.
</Note>

### 1.2 Bulk import & export

For larger groups, use **Import contacts**: download the sample CSV file, fill it in, and upload it. The platform flags duplicates, invalid email addresses, or unsupported languages before the import. You can also export the current list.

### 1.3 User detail (Hub)

For a Hub user, the detail page shows the Wenite points balance, the Hub activity level (Curious, Active, Dedicated), redemption history, and the option to grant extra Wenite points.

## 2. Permissions

On the **Permissions** tab, you determine exactly what a client or user can see and do. The permission model works on multiple levels.

### 2.1 Feature level

For each feature, you set whether the user can **browse** (view) and/or **manage**:

| Feature           | Examples                            |
| ----------------- | ----------------------------------- |
| Client management | View clients vs. create/edit/delete |
| Users             | View users vs. manage               |
| Dashboard         | Access to the results dashboard     |
| Surveys           | View surveys vs. create/manage      |
| Reports           | View reports                        |
| Library           | View library vs. manage             |
| Marketplace       | View offers vs. manage              |
| Content           | View articles vs. manage            |
| Projects          | View projects vs. manage            |

### 2.2 Tab level

Within Dashboard, Surveys, and Projects, you can enable or disable specific tabs (e.g. show only Overview and KPIs, but not Questions).

### 2.3 Data and filter level

Filter permissions restrict which socio-demographic filter values a user can view or apply. This lets a department head see only their own department, for example. For surveys, you also control whether exporting is allowed and which parts can be exported.

<Tip>
  Give an HR manager **Viewer access** by default, limited to the relevant dashboard tabs, and restrict filters to the groups relevant to them. Start restrictive and open up specific tabs/filters as trust and need grow — it's much less awkward than walking back access someone's already had.
</Tip>

## 3. Support mode (impersonating a client)

As a consultant, you can use the company switcher to step into the context of a specific client and see the portal exactly as that client sees it — without sharing login credentials or modifying the client's account. This is useful for support and for verifying permissions.

<Note>
  Support mode shows the portal in the client's role; you do not make changes on the client's behalf unless you deliberately choose to.
</Note>

## Recommended workflow

1. **Set up permissions right after creating the client** (only possible after creation): start from a minimal set and expand as needed.
2. **Add users** with the right role; use bulk import for large groups.
3. **Restrict filters per user** so everyone sees only the relevant data.
4. **Verify via support mode** that the client sees exactly what's intended.
