# Roles and permissions

Everything in Vintage belongs to an **organization**: the account for your bank or credit union, holding its portfolio, uploads, fields, and team. Each member of an organization has exactly one of three **roles**, which decide what that person can do there:

- **Admin**: full control. Everything an editor can do, plus managing the team and the organization's settings. Whoever creates an organization is its first admin.
- **Editor** (shown as "View and update"): full access to the data. Can upload, map, and finalize, and can change how the organization's fields are read. Cannot manage the team or rename the organization.
- **Viewer** (shown as "View only"): read-only. Can explore the portfolio and model it, but cannot upload or change any data.

A person can belong to several organizations, with a different role in each. Their role in the **active** organization, the one they are working in, is the one that applies.

## What each role can do

| Action | Admin | Editor | Viewer |
|---|---|---|---|
| View the Portfolio screen, search loans by protected ID (the scrambled stand-in for a Loan ID) | Yes | Yes | Yes |
| Build a Segment (saved for you alone) | Yes | Yes | Yes |
| Use the Modeling screen, price a loan, save your own pricing assumptions | Yes | Yes | Yes |
| Download charts and tables | Yes | Yes | Yes |
| Open Uploads and Upload History | Yes | Yes | No |
| Start an upload, remove PII, map columns, classify values, finalize | Yes | Yes | No |
| Resume a draft, delete an upload or a file | Yes | Yes | No |
| Open the Fields screen: retype custom fields, edit value vocabularies, reporting basis (monthly versus running-total amounts), the Interest Rate format, and Portfolio semantics | Yes | Yes | No |
| Settings › Profile: your name, email, password, sign out of other devices | Yes | Yes | Yes |
| Settings › Organization: rename the organization | Yes | Read-only | Read-only |
| Settings › Team: invite, change roles, remove members, resend or withdraw invites | Yes | Read-only | Read-only |
| Settings › Security: manage the IP allowlist | Yes | Not shown | Not shown |
| Create a new organization (from the organization switcher) | Yes | Yes | Yes |

A person who creates a new organization becomes its admin, whatever their role elsewhere.

Changes made on the Fields screen apply to the whole organization, and most of them re-read the whole portfolio, so they change what every member sees. That is why they belong to admins and editors. A Segment and pricing assumptions are personal: each member's are saved for them alone and change nothing for anyone else.

## Roles are enforced, not only hidden

A viewer does not see **Upload** or **Fields** in the navigation at all. But hiding is not the protection: a viewer who reaches an edit-only screen by any means sees a page saying they don't have access, and Vintage refuses the action itself. A non-admin likewise does not see **Security** in Settings, and going to it directly is refused.

Where a non-admin can see a settings area, it is read-only. The Team table shows roles as plain text with no controls, and the invite form is present but disabled with a note that only an admin can invite.

Roles also decide where a person lands after signing in. Anyone lands on Modeling by default. An admin or editor whose organization has no loans yet lands on the **Uploads** page instead, while a viewer always lands on Modeling. A viewer in an empty organization sees the empty state without the button to start an upload.

## Rules that protect the organization

- **New invitees default to Viewer**, the safest role. An admin can choose Editor at invite time, or change the role later.
- **An organization always keeps at least one admin.** Vintage refuses any change that would leave it with none: you cannot demote or remove the last admin.
- **An admin cannot change or remove themselves** from the Team screen.
- **Inviting someone who is already a member is refused**, including the admin's own address.
- **Inviting an address that already has a pending invite updates that invite** rather than creating a second one: the name, role, and inviter are replaced and the email is sent again. Inviting again is how an admin fixes a wrong role on a pending invite.
- **Removing a member preserves their work.** Their past uploads stay in the organization's history, still showing who uploaded them, and removing a person never deletes their account.

Every refusal is explained on screen in plain language. A role never quietly snaps back.

**When a member is removed:** If the organization a person was working in is one they no longer belong to, for example because an admin removed them, Vintage quietly switches them to another organization they belong to rather than showing them nothing.

## During your first portfolio's setup

When your organization is new, the Vintage team finishes setting up its first portfolio. While that is under way, **Modeling, Portfolio, and Fields are withheld from every member**, whatever their role, and signing in lands an admin or editor on Uploads and a viewer on a page explaining the wait. A Vintage teammate joins the organization as an **editor** to finish the work. They appear on your Team list as **Vintage support**, with the ordinary **Remove** control, so your admin can end that access at any time. When the work is done, the teammate leaves. See [Your first upload](/uploading/your-first-upload/).

## Related

- [Accounts and organizations](/getting-started/accounts-and-organizations/)
- [Team and organization settings](/account/team-and-organization-settings/)
- [Security and data protection](/reference/security-and-data-protection/)
- [Fields](/portfolio/fields/)
- [Upload History](/uploading/upload-history/)