The SoSafe Manager has 4 admin roles. This article covers what each one can access and how to assign it, so people get the permissions their job needs without seeing individual training results they aren't authorized to see.
Overview
The 4 roles map to distinct jobs: running the platform, reading reports, provisioning users, and launching campaigns.
- Administrator
- Analytics Viewer
- User Manager
- Campaign Manager
Aggregated vs. individual data
All roles respect your tenant-wide data privacy setting (individual or person-specific reporting vs anonymous or aggregated reporting. This is a crucial distinction.
| Data type | Description | Example |
|---|---|---|
| Aggregated data | Numbers and group KPIs that do not include names or personal identifiers | "68% of the Engineering team completed the module" |
| Individual data | Specific training or simulation results tied directly to identifiable individuals | "Max Mustermann clicked the simulated phishing link on March 14" |
Role permissions summary
| Role | User & group management | Campaign management | Aggregated analytics | Individual results | Platform settings |
|---|---|---|---|---|---|
| Administrator | Full | Full | All groups | Only if enabled | Full |
| Analytics Viewer | None | None | Depends on scope | Depends on scope | None |
| User Manager | Full | None | None | None | SSO & SCIM only |
| Campaign Manager | None | Full | Campaign-level | Aggregated only | Whitelisting view |
Detailed role breakdown
Administrator
The Administrator can do anything in your organization's platform, including handing out roles to everyone else.
- Capabilities: Every platform setting, user account, campaign, and role assignment
- Data visibility: Aggregated KPIs and individual results (if available), across all user groups
- When to use: CISOs, security officers, and lead IT administrators. We recommend keeping this to 1–3 people per organization
Analytics Viewer
Read-only access to Analytics data based on scope. No access to platform settings or user management.
- Capabilities: View campaign and e-learning reporting dashboards. No editing campaigns, no managing users, no changing settings
- Scope: The whole organization (full access), specific groups, or a manager's direct reports
-
Data visibility: depends on scope
- Full access: Same Analytics access as Administrators
- Direct reports: Access to data of their direct reports only (managed through the "Responsible person" user data column)
- Anonymous: Access to aggregated data and dashboards only.
- When to use: Department managers, auditors, or compliance officers who track progress but shouldn't change anything
User Manager
The User Manager handles accounts and the directory plumbing that keeps them in sync.
- Capabilities: Create and remove users, user data spreadsheet uploads, configure SCIM or SSO
- Data visibility: No analytics at all. Account metadata (names and email addresses) is visible; training progress and phishing simulation results are not
- When to use: HR administrators and IT helpdesk teams who handle onboarding but shouldn't see security scores
Campaign Manager
Campaign Managers can set up awareness programs (Phishing Simulations and E-Learning).
- Capabilities: Build and launch phishing simulations and e-learning, plus read access to whitelisting configuration so they can coordinate with local IT
- Data visibility: Full access to campaign analytics, no company-level dashboards
- When to use: Regional security champions or branch leads who need to run their own campaigns without waiting on a central admin
How to assign roles
You need the Administrator role yourself to create new admin users.
- Log in to SoSafe Manager and navigate to Settings / Admin users.
- Select Add admin, or select the pen icon in the row of an existing user.
- In the Role & Rights section, select one of the 4 role cards.
- If applicable: Set the data scope for an Analytics Viewer
- If applicable: Set the data scope for an Analytics Viewer
- Select Save.
Frequently asked questions
Can an admin role have custom permissions?
No. The 4 default roles are pre-configured, because their fixed boundaries are what keep the security and privacy outlined above intact.
Which roles are compliant with strict privacy guidelines?
Campaign Manager and User Manager never expose individual performance data. Analytics Viewer data insights depend on the scope as well as the tenant-wide reporting settings. Administrators always have full access while maintaining the boundaries set by your reporting settings.
Can a user hold multiple admin roles at the same time?
Not at as of September 2026. Each user is assigned 1 primary administrative role. We are working on multi-role assignment for a future release.