Roles & Permissions (Role-Based Access Control)

Roles & Permissions lets account owners control what each team member can see and do in LeadCenter. A role is a set of permissions, such as viewing accounts, creating templates, managing users, or seeing records across the account.

Use roles to give each team member the access they need for their work without giving everyone the same level of access.


Where to Find Roles & Permissions

  1. Open Settings.
  2. Go to User & teams.
  3. Open Roles & Permissions.
  4. Open a role to review or update its permissions.

To assign a role to a team member, go to the Users page and select the appropriate role for that user.


Built-In Roles

Every account includes four built-in roles:

  • Owner — Has full access to the account. This role is locked and cannot be edited or removed. An Owner’s role cannot be changed from the role selector.
  • Admin — Has broad management access across the account.
  • Editor — Can work with records and content, with fewer administrative permissions.
  • Limited — Has the most restricted access. By default, Limited users only see records they own or are assigned to.

Note: Built-in roles cannot be deleted.


Create a Custom Role

Custom roles let you create access levels that match how your team works.

  1. Go to Settings and open Roles & Permissions.
  2. Click Create role.
  3. Enter a role name and optional description.
  4. Select the permissions the role should have.
  5. Click Save.

Note: A new custom role starts with no permissions selected. Add only the permissions that role should have.

You can edit or delete custom roles later as your team’s responsibilities change.


Review Permissions

Permissions are grouped by area, such as Financial Accounts, Templates, Marketing, Forms, and Email Setup. In each group, the View permission appears first because many other actions depend on being able to view that area.

Use these tools to review permissions more easily:

  • Search — Find a permission by name.
  • Show selected only — Review only the permissions already included in the role.
  • Select all and Clear all — Start from a known state when setting up or revising a role.

Document Permissions

Account owners and administrators can use the Documents permissions on a role to control who may view, add, update, or delete documents.

Configure Document Permissions

  1. Open Settings.
  2. Go to User & teams, then open Roles & Permissions.
  3. Create a role or open an existing role.
  4. Expand the Documents section.
  5. Turn the required permissions on or off, then save the role.

Available Permissions

  • View documents — Open the Documents page and preview or download documents.
  • Add documents — Upload documents from the Documents page, contacts, households, notes, tasks, and financial accounts.
  • Update documents — Change a document’s name, category, description, and Secure Document Portal visibility.
  • Delete documents — Archive or remove uploaded documents.

Default access: Owner, Admin, Editor, and Limited roles include all four document permissions by default. An account owner or administrator can remove individual permissions from an editable role.

Document Visibility and Contact Access

Document permissions control the actions a user may perform. The See all contacts & records (not just owned) permission separately controls which contacts’ documents the user can access.

  • With this permission, the user may access documents across the account.
  • Without it, the user is limited to documents connected to contacts they own or are assigned to.

Important Notes

  • Event attachments follow the existing Events permissions.
  • Managing document categories remains part of the existing Settings access.
  • Removing a document permission also blocks direct links and related document actions.
  • LeadCenter AI document tools follow the same View documents permission.

Financial Account Type Visibility

For financial-advisor accounts, financial account visibility is separated by account type:

  • AUM
  • Insurance
  • Financial Planning

Important: Granting View accounts by itself does not show financial accounts. The role must also include at least one account type visibility option. If no account type is selected, account lists remain empty by design.


See All Contacts or Assigned Contacts Only

The See all contacts & records (not just owned) permission controls whether a team member can access every contact or only contacts connected to their current assignments.

  • Permission enabled: The team member can access contacts across the account.
  • Permission disabled: The team member can access a contact when they or a team they belong to match an eligible assignment.

Assignments That Provide Contact Access

  • Owner
  • Scheduler
  • Writing advisor
  • Servicing advisor
  • Wealth manager

Writing advisor, servicing advisor, and wealth manager can be assigned to a person or a team. When a team is assigned, each current member of that team receives access. Owner and scheduler assignments are always assigned to a person.

Where Assigned-Contact Visibility Applies

  • Contacts Dashboard and contact details
  • Global search results for contacts and their appointments
  • Financial accounts and their related transactions and assets
  • Documents
  • Calendar appointments connected to a contact
  • Event attendees and Financial Questionnaire submissions
  • Contact activity

Email, text message, and call lists continue to show only contacts the team member owns or is the scheduler for. Writing advisor, servicing advisor, and wealth manager assignments do not add contacts to those lists.

Visibility follows the current assignment. If an assignment changes from a team to one person, the other team members lose that access unless they still match another eligible assignment.


What Users See When Permissions Are Limited

LeadCenter hides pages, tabs, fields, buttons, and menu items when a user’s role does not include the related permission. If a user tries to open a protected page or perform a restricted action directly, LeadCenter blocks the action.

Sensitive financial figures, such as commission or fee amounts, are not displayed when the user’s role does not include the matching permission.


How Permissions Apply to Troy AI

Troy AI follows the same access rules as the rest of LeadCenter. It can only find, summarize, or change information that the current user is allowed to access. There is no separate permission setting for Troy AI.

  • Troy only uses contacts, accounts, notes, tasks, emails, documents, events, and other records the user is allowed to view.
  • If a role cannot access a record or action, Troy declines the request and explains that the user does not have permission.
  • Team members with assigned-contact access only receive results for their contacts and records connected to those contacts.
  • Commission and fee details remain hidden in Troy when the user cannot view those figures on the account record.

For questions about a household, name a contact in the household or open that contact before asking Troy. Troy can review an accessible contact’s household without displaying households across the entire account.

Results may differ between team members because each person’s role and assignments determine what Troy can access. If Troy cannot find expected records, check the same permissions, assignments, and page filters that control the corresponding list in LeadCenter.

AI-generated answers may be incomplete or incorrect. Confirm important details on the original contact, account, or related record before taking action.


Troubleshooting Access Issues

If a user cannot see a page, list, button, or record they expected to see, check their role first.

  • Confirm the role includes the related View permission.
  • For financial accounts, confirm at least one account type visibility option is selected.
  • For assigned-only users, confirm the record is owned by or assigned to that user.
  • If Troy declines a request, confirm the user can open the same record or perform the same action directly in LeadCenter.
  • After changing a role, ask the user to refresh the page or sign out and back in if their screen has not updated.

Best Practices

  • Give each team member the lowest level of access that still lets them do their work.
  • Use custom roles for job-specific access, such as operations, marketing, service, or administrative responsibilities.
  • Review roles when team responsibilities change.
  • Keep personal areas, such as a user’s own profile, notification preferences, and calendar, available where appropriate.
  • Check roles before troubleshooting missing pages or empty lists.

Need more help?

If you can't find the answers you're looking for, our support specialists are available to answer your questions and troubleshoot if necessary.

  • Phone Call (888) 291-7116. Our main hours are Monday to Friday 7 am-5 pm Central Time.
  • Support Send your questions and inquiries via email to support@leadcenter.ai. A support ticket will be created and one of our team members will get back to you as quickly as possible.