This service is designed and operated in alignment with FedRAMP Moderate security requirements when configured in accordance with the provider’s documented recommendations. Customers acknowledge and agree that failure to implement or maintain the recommended security configurations may increase risk and that they assume full responsibility for any resulting security incidents, data loss, or service impacts. The provider disclaims liability for issues arising from customer-managed configurations that deviate from recommended practices.
NextStage uses a role-based access control system to manage what users can view, create, edit, and delete within your workspace.
Each user's permissions are determined by their assigned role. Permissions are organized by scope — including pipelines, opportunities, past performance, key personnel, contacts, organizations, tasks, notes, documents, reports, and administrative settings — and each role grants specific View, Create, Edit, Delete, and Template rights within each scope.
Default User Roles
NextStage includes seven built-in roles. When you invite a user, you select their role — there is no preselected default.
Role | Description |
Admin | Full administrative access to the workspace, including members, billing, roles, and all pipelines. |
Manager | Manage pipelines, opportunities, and content across the workspace without workspace administration (security, integrations, and other workspace settings). |
Member | Standard access for day-to-day work: create and manage opportunities, contacts, organizations, tasks, notes, documents, and reports. |
Analyst | Limited editing access, focused on reporting and analysis. |
View Only | Read-only access with no editing permissions. |
View Only Guest | For external collaborators: read-only access to pipelines, opportunities, tasks, notes, and documents. |
Guest Collaborator | Everything a View Only Guest can see, plus editing opportunities and creating and editing tasks, notes, and documents. |
Guest Roles for External Collaborators
The two Guest roles are designed for people outside your organization — teaming partners, consultants, or reviewers — who need access to specific work without broader workspace visibility.
Use View Only Guest when a partner only needs to review.
Use Guest Collaborator when a partner needs to contribute — editing opportunities or adding tasks, notes, and documents.
For tighter control, combine a Guest role with pipeline-level access so the guest only sees the pipelines they're working on. See Pipeline Permissions for details.
Granting Pipeline Access When Inviting a User
When inviting a user, you can grant access to specific pipelines directly from the invite window. For each pipeline that has user-level permissions enabled, select the role that user should have within that pipeline.
This is the recommended way to onboard external collaborators: assign a Guest role, then grant access only to the relevant pipelines.
What Admins Can Do
Admins can:
Invite and remove users
Change user roles and create custom roles
Edit pipeline templates and custom fields
Configure integrations
Modify security settings
Permanently delete opportunities, pipelines, and other data
What Members Can Do
Members can:
Create and update opportunities
Manage pipeline information, contacts, and organizations
Create and view reports
Add notes, tasks, and documents
Members cannot:
Edit workspace settings or integrations
Manage user accounts
Permanently delete critical system data
Viewing and Managing User Roles
Admins can manage user roles from the Admin page.
Navigate to Admin in the left menu
Click the Users tab
Locate the user
Select a role from the Role dropdown next to their name
Changes take effect immediately.
Viewing Role Permissions and Creating Custom Roles
To view the permissions each role grants:
Go to Admin
Click the Roles tab
Each role shows a permissions grid organized by scope — Workspace, Pipeline, Opportunities, Past Performance, Key Personnel, Tasks, Documents, Reports, Contacts, Organizations, Notes, SharePoint Integration Settings, Dummy User, Nexus AI, and Content Library — with View, Create, Edit, Delete, and Template columns.
If the built-in roles don't fit your team, click + New Role on the Roles tab to create a custom role with exactly the permissions you need.
About Dummy Users: Dummy Users are placeholder accounts representing people who don't need a NextStage login — useful for assigning capture team roles to teammates who don't use the platform. They don't count toward your licensed users. The Dummy User scope controls which roles can create, edit, and delete them.
Disabling User Access
Disabling a user prevents them from accessing the workspace without deleting their account.
Go to Admin
Click the Users tab
Change the user's Status to Disabled
This immediately removes workspace access.
Restricting Workspace Access (Recommended)
To improve security, you can restrict workspace access to invite-only.
Go to Admin
Click the Security tab
Enable Make workspace invite only
Invitations are single-use and expire after 7 days.
Deleting Users
Admins can permanently remove users from the workspace.
Go to Admin
Click the Users tab
Click the Trash Can icon next to the user
What Happens When a User Is Deleted
Dashboard ownership is transferred to the admin performing the deletion
Saved searches remain in the workspace
Notes and activity history remain
Tasks are unassigned
Pending invitations created by that user are cancelled
No opportunity data is lost.
Best Practices
We recommend:
Limiting Admin access to system administrators only
Using Manager for team leads who run pipelines but shouldn't change workspace settings
Assigning Member access to capture managers and BD staff
Using View Only access for internal leadership and reviewers
Using Guest roles with pipeline-level access for teaming partners and external collaborators
Enabling invite-only workspace access
