Company administrator and superadministrator — who bypasses what
A company administrator bypasses all permission checks in their company. They do not bypass 2FA or reach outside the company — that requires a platform superadministrator.
There are two levels that bypass ordinary permission checks — and they differ more than their names suggest.
Step by step
Make a role a company administrator
- Go to Team and access → Roles and permissions. The Team and access screen opens on the Roles and permissions tab with the Company roles list.
- Click the pencil icon with the Edit role tooltip next to the chosen role — or click Add role to create one.
- In the window, fill in Role name (without it, the save button is inactive) and optionally Description.
- On the Company administrator card, labelled Full access to all features and data, switch it on.
- The Module permissions and Field permissions tabs disappear and a Full access enabled warning appears in their place. This confirms that the switch is active.
- Click Update role (or Create role for a new one).
- The 2FA verification required window appears. Enter the code from your authenticator app in Verification code and click Confirm. The save completes automatically (2FA confirmation when changing permissions).
- The role window closes and the list refreshes. The role now has a red Full access chip in the Permissions column instead of Modules: N, and its icon changes to a crown.
If something goes wrong, you will see Could not save role — the window stays open with the selected settings.
Note: when saving a role with the switch enabled, field permissions are not sent at all — the tab is gone, so there is nothing to save. They remain in the database as they were and return to the window when the switch is turned off (Field permissions — individual fields and individual actions).
Check whether a specific person is an administrator
- Go to the User accounts tab.
- In the person’s row, click the three-dot menu and choose Effective permissions. This item is visible only to a company administrator and the superadministrator.
- In the Effective permissions window, an administrator sees one sentence instead of tables: This user has full administrative access (manage everything).
- Close the window with Close.
You can also see this in the list without opening the window: roles with the administrator switch have red chips in the Roles column; other roles have blue ones (User list — cards, columns, and filters).
Company administrator
This switch is on the role (Creating and editing a role — the two-tab window). A person with such a role:
- bypasses all module permissions in their company;
- bypasses all field permissions;
- can see everything belonging to the active company.
What they do not bypass:
- 2FA confirmation for sensitive operations (2FA confirmation when changing permissions);
- company boundaries — other companies’ data remains invisible, just as it is for everyone else;
- protection for colleagues — they cannot reset a superadministrator’s password, delete a superadministrator, or delete another administrator in the same company (Forgotten password and blocked access — what an administrator can and cannot do);
- the Platform section, which is explicitly disabled.
Everyone has one permission
Every signed-in user, even without a single role, has read access to the knowledge base. This gives a new person who has not yet been assigned a role somewhere to read what is going on.
How many administrators to have
At least two. An administrator cannot recover their own account after losing 2FA (Forgotten password and blocked access — what an administrator can and cannot do), and no one else can help except another administrator.
Technical accounts are managed by an administrator only
An external program — n8n, WAPRO, or a custom script — does not use an employee account or their personal token (API keys — your personal tokens). It gets a technical account: a separate program account, permanently assigned to one company, with its own API token that has a limited validity period.
A company administrator creates it and issues its tokens under Settings → System → Program access (API). There is no separate role permission for this, and it cannot be granted to anyone: such an account’s token works with company administrator rights, so permission to issue one would be worth exactly as much as an administrator role. Every change requires fresh 2FA confirmation.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo