
Every member of your Mergepoint workspace has two things assigned to them: a role and one or more permission sets. These are separate concepts that work at different levels.
A role is a title. It describes who you are in the organisation — for example Head of Finance, Field Operator, or Software Engineer. Roles appear on your profile and in team views.
Each member has exactly one role. It is purely descriptive and does not control what you can see or do in the product. Changing someone's role does not change their access.
Permission sets are what actually govern access. A permission set is a named bundle of rules that defines:
Unlike roles, a member can belong to multiple permission sets at the same time. Their effective access is the broadest combination of all their sets.
| Role | Permission Set | |
|---|---|---|
| What it is | Identity label / job title | Access control bundle |
| How many per user | Exactly one | One or more |
| Controls what you see | No | Yes |
| Controls what you can do | No | Yes |
| Changes access immediately | No | Yes |
A member labelled "Finance Analyst" (role) might be in both a "Finance Team" permission set (giving them access to forms and task submission) and a "Reporting" permission set (adding read access to Analytics). Their role says who they are; their permission sets say what they can do.
If someone asks "why can not I see the Analytics tab?", the answer is in their permission sets — not their role. And if you want to temporarily expand access for a project, you add them to an additional permission set rather than changing their role or creating a new one from scratch.