Global roles

Some roles are not bound to specific resources and are therefore global. This page lists all predefined global roles and their permissions.

Client App Developer

This role includes the permissions required for developers to manage client apps. The iokian developing the client app should have these permissions.

- access_all_providers
- access_all_products
- access_all_operators
- access_management_interface
- manage_clients
- manage_universal_links
- manage_firebase_credentials
- manage_user_segments
- read_api_documentation
- take_over_provider_account_as_kam

iokian

This role is intended for all iokians with an @ioki.com email address and includes the permissions that all of them should have.

- read_kompendium
- write_kompendium

Internal Reporter

This role can view global reports.

- view_global_reports

PM, KAM, LAM

This role includes the permissions required by PMs, KAMs, and LAMs who need visibility into product and provider setups and who must perform specific tasks.

- access_all_providers
- access_all_products
- access_all_operators
- access_management_interface
- manage_universal_links
- manage_matching_logs
- view_global_reports
- take_over_provider_account_as_kam

Product and Provider Setup Admin

This role includes the permissions required to work with products and providers on a global level. As the name suggests, this role is used to set up providers and assign products to them.

- access_all_providers
- access_all_products
- access_all_operators
- access_management_interface
- manage_products
- manage_providers
- assign_admins_to_resources
- manage_universal_links

Route Admin

This role includes the permissions required to administer the ioki Route app.

- access_all_providers
- access_all_products
- access_all_operators
- access_route_admin_interface

System Admin

This role includes the permissions required to administer the system.

- access_all_providers
- access_all_products
- access_all_operators
- access_all_users
- access_management_interface
- access_system_informations
- access_email_deliveries
- access_platform_api_usages
- access_all_admins
- manage_clients
- manage_universal_links
- manage_products
- manage_providers
- manage_firebase_credentials
- assign_admins_to_resources
- read_api_documentation
- read_kompendium
- write_kompendium
- manage_platforms
- export_product_settings
- import_product_settings
- manage_rbac_system
- manage_contacts
- manage_all_webhooks
- take_over_provider_account_as_kam
- access_route_admin_interface

Web Booking Admin

This role includes the permissions required to administer the web booking client. See Configure web booking for what these permissions unlock.

- access_all_providers
- access_all_products
- access_all_operators
- access_webbooking_admin_interface