Skip to main content

User Management, Roles, and Permissions

How NextStage role-based access control works: default and Guest roles, permission scopes, custom roles, pipeline access at invite, and managing, disabling, or deleting users.

Written by Matt Miller

This service is designed and operated in alignment with FedRAMP Moderate security requirements when configured in accordance with the provider’s documented recommendations. Customers acknowledge and agree that failure to implement or maintain the recommended security configurations may increase risk and that they assume full responsibility for any resulting security incidents, data loss, or service impacts. The provider disclaims liability for issues arising from customer-managed configurations that deviate from recommended practices.

NextStage uses a role-based access control system to manage what users can view, create, edit, and delete within your workspace.

Each user's permissions are determined by their assigned role. Permissions are organized by scope — including pipelines, opportunities, past performance, key personnel, contacts, organizations, tasks, notes, documents, reports, and administrative settings — and each role grants specific View, Create, Edit, Delete, and Template rights within each scope.


Default User Roles

NextStage includes seven built-in roles. When you invite a user, you select their role — there is no preselected default.

Role

Description

Admin

Full administrative access to the workspace, including members, billing, roles, and all pipelines.

Manager

Manage pipelines, opportunities, and content across the workspace without workspace administration (security, integrations, and other workspace settings).

Member

Standard access for day-to-day work: create and manage opportunities, contacts, organizations, tasks, notes, documents, and reports.

Analyst

Limited editing access, focused on reporting and analysis.

View Only

Read-only access with no editing permissions.

View Only Guest

For external collaborators: read-only access to pipelines, opportunities, tasks, notes, and documents.

Guest Collaborator

Everything a View Only Guest can see, plus editing opportunities and creating and editing tasks, notes, and documents.


Guest Roles for External Collaborators

The two Guest roles are designed for people outside your organization — teaming partners, consultants, or reviewers — who need access to specific work without broader workspace visibility.

  • Use View Only Guest when a partner only needs to review.

  • Use Guest Collaborator when a partner needs to contribute — editing opportunities or adding tasks, notes, and documents.

For tighter control, combine a Guest role with pipeline-level access so the guest only sees the pipelines they're working on. See Pipeline Permissions for details.


Granting Pipeline Access When Inviting a User

When inviting a user, you can grant access to specific pipelines directly from the invite window. For each pipeline that has user-level permissions enabled, select the role that user should have within that pipeline.

This is the recommended way to onboard external collaborators: assign a Guest role, then grant access only to the relevant pipelines.


What Admins Can Do

Admins can:

  • Invite and remove users

  • Change user roles and create custom roles

  • Edit pipeline templates and custom fields

  • Configure integrations

  • Modify security settings

  • Permanently delete opportunities, pipelines, and other data


What Members Can Do

Members can:

  • Create and update opportunities

  • Manage pipeline information, contacts, and organizations

  • Create and view reports

  • Add notes, tasks, and documents

Members cannot:

  • Edit workspace settings or integrations

  • Manage user accounts

  • Permanently delete critical system data


Viewing and Managing User Roles

Admins can manage user roles from the Admin page.

  1. Navigate to Admin in the left menu

  2. Click the Users tab

  3. Locate the user

  4. Select a role from the Role dropdown next to their name

Changes take effect immediately.


Viewing Role Permissions and Creating Custom Roles

To view the permissions each role grants:

  1. Go to Admin

  2. Click the Roles tab

Each role shows a permissions grid organized by scope — Workspace, Pipeline, Opportunities, Past Performance, Key Personnel, Tasks, Documents, Reports, Contacts, Organizations, Notes, SharePoint Integration Settings, Dummy User, Nexus AI, and Content Library — with View, Create, Edit, Delete, and Template columns.

If the built-in roles don't fit your team, click + New Role on the Roles tab to create a custom role with exactly the permissions you need.

About Dummy Users: Dummy Users are placeholder accounts representing people who don't need a NextStage login — useful for assigning capture team roles to teammates who don't use the platform. They don't count toward your licensed users. The Dummy User scope controls which roles can create, edit, and delete them.


Disabling User Access

Disabling a user prevents them from accessing the workspace without deleting their account.

  1. Go to Admin

  2. Click the Users tab

  3. Change the user's Status to Disabled

This immediately removes workspace access.


Restricting Workspace Access (Recommended)

To improve security, you can restrict workspace access to invite-only.

  1. Go to Admin

  2. Click the Security tab

  3. Enable Make workspace invite only

Invitations are single-use and expire after 7 days.


Deleting Users

Admins can permanently remove users from the workspace.

  1. Go to Admin

  2. Click the Users tab

  3. Click the Trash Can icon next to the user


What Happens When a User Is Deleted

  • Dashboard ownership is transferred to the admin performing the deletion

  • Saved searches remain in the workspace

  • Notes and activity history remain

  • Tasks are unassigned

  • Pending invitations created by that user are cancelled

No opportunity data is lost.


Best Practices

We recommend:

  • Limiting Admin access to system administrators only

  • Using Manager for team leads who run pipelines but shouldn't change workspace settings

  • Assigning Member access to capture managers and BD staff

  • Using View Only access for internal leadership and reviewers

  • Using Guest roles with pipeline-level access for teaming partners and external collaborators

  • Enabling invite-only workspace access

Did this answer your question?