Sometimes you don't want your entire team to have the same access to your talent data in Thrive—that's why we've given Admins extensive control over what users can see and do within the system through user roles and permissions.
If you’re new to Thrive and an Admin user, we recommend you configure all role types before inviting your team members into the system as users.
Read this article to learn:
Roles you can assign (including custom roles)
Which permissions team members possess based on their assigned role
How to invite new team members into Thrive and assign them a role
System Roles Versus Custom Roles
Thrive includes six pre-set System Roles that are available out of the box. We also allow for Custom Roles that you configure based on the permissions options available. You can also duplicate a System Role and turn it into a Custom Role by adjusting the individual permissions.
System Roles
Read through the descriptions below to learn about the default permissions for each System Role.
Admin
Admins play a critical role in Thrive, as they are responsible for granting their teammates access and configuring the tenant in a way that matches their organization’s executive talent processes. This configuration includes creating project stages, off-limits definitions, custom fields, and tags used by all other users within the system. They also handle integrations.
Because of their all-encompassing role, Admins have all permissions enabled by default.
Partner
Partners have full permissions enabled by default to manage people, companies, projects, scorecards, and compensation.
Partners are unable to create new users, disable existing users, or assign user permissions. They also lack visibility into user roles and permissions, as well as the ability to impersonate users on their team.
Recruiter
Recruiters have all permissions enabled for people, meaning they can add, edit, view, and delete people from the team’s talent database. For companies and projects, they can add, edit, and view, but not delete. They can update a project’s status, but are unable to view compensation data on person profiles.
Researcher
Researchers have all permissions enabled for people, companies, and scorecards, meaning they can add, edit, view, and delete these records.
Engagement Coordinator (Executive Search Only)
Engagement Coordinators typically handle search scheduling and project management related to executive search activity. These users have view-only access to see scorecard templates, people, and companies, which means they can see records but not add, edit or delete these records. They can create, edit, and view projects, including the ability to update project status and see compensation data for candidates. They are not able to delete projects.
Hiring Manager
Hiring managers have the most limited permissions. They can only view people and projects, but they cannot schedule events or see private notes from others unless explicitly shared. They can add notes and scorecards and like candidates to prioritize them.
Custom Roles
Thrive also allows for Custom Roles, which Admins can configure to meet the different needs of your team. There are two ways to create a Custom Role.
Create a Custom Role From Scratch
Navigate to the Admin section by clicking the settings cogwheel (⚙️) in the bottom-left corner.
Select Roles & Permissions from the left-hand menu.
Click the + Role button at the top right.
Enter a clear Name and Description for the role.
Select the specific permissions you want to grant for this role.
Click Create in the bottom right corner to create the new role.
Create a Custom Role by Duplicating a System Role
Navigate to Admin Portal > Roles and Permissions
Select the system role you wish to duplicate
Click on the ellipses (the three dots, located on the far-left)
Re-name your custom role and choose the customized permissions
How to Manage Custom Roles
From the Roles & Permissions screen, you can manage any custom role you've created. Click the
to the right of the role's description to Edit, Duplicate, or Delete it.
Example Custom Roles
Let’s say I wanted to created an External Recruiter Custom Role to differentiate their activity from my internal team. I could start by duplicating the default Recruiter role, giving it a new name, and writing a description. From there, I would select the individual permissions I wanted to assign.
In this example, I’m allowing the External Recruiter role to view other users in the system as well as their permissions. They can change custom field values, but they can’t create new ones. Similarly, they can add tags to people, companies, and projects, but they can’t create new ones. They are able to create new scorecard templates, but they cannot edit any existing templates.
They can create, edit, and view people and companies, but they can’t delete these records from the talent database. They can view and edit existing projects, but are unable to create or delete projects. They can update a project’s status, but are not able to view compensation data.
Overview of User Permissions
For each Thrive user, you can choose different permissions depending on how they use your talent database. Below are the available permissions and what they allow you to do.
Section | Permission | Description |
Admin | Manage Users | Invite new team members and assign a user role |
Impersonate Users | See the system exactly as another user with different permissions would see it
Important Note: This feature is powerful because it allows you to take action with the assumed permissions of the user you impersonate. For example, you could add a note as the user you are impersonating. That is why only Admins and Recruiters have this turned on by default.
|
|
Manage Roles | Build custom roles and see in detail what each role is permitted to do and not do |
|
Custom Fields | Configure custom fields and select visibility |
|
Manage Tags | Add tags to __, ___, and ___ |
|
Manage Scorecard Templates | View existing scorecard templates, create new ones, delete old ones, and apply function tags |
|
People | Manage People | View people data, create new people, and edit people |
Companies | Manage Companies | View company data, create new companies, edit company information, and delete companies |
Projects | Manage Project | View project data, create new projects, and edit project information
Note: There are also project-level permissions that further restrict access. Read more here.
|
Manage Project Status | Update a project's status
Note: If users select closed or canceled, you will be prompted to add a reason
|
|
View Compensation | View estimated compensation and offer compensation |
|
Permission Levels
Thrive utilizes a permissioning model that currently supports create, edit, and view permissions for each record type.
Important Note: Currently, users are only able to delete notes, outreaches, scorecards, experience, events, and compensation record types. Company, people, and project records cannot be deleted, even with Admin permissions. If you need to delete a person, company, or project record, please contact support.
Permission Level | Create | Edit | View | Delete
|
Description | Add a new record | Edit an existing record | View a record | Delete a record |
Example (People) | Add or import a new person to your talent database | Select an existing person in your talent database and update individual fields like location, email, notes, experience, and more | See a person in the talent database without the ability to edit any information | Delete a person from your database
Note: This permission is currently unavailable to all users, including Admins. |
Impersonate User Permission
The Impersonate User permission is designed to help users understand how other users will see specific data within Thrive. Within Thrive’s default system roles, this permission is only available to Admins. If Recruiters or other users need to preview what clients and hiring managers can see in Thrive ahead of sharing, they can achieve this by navigating to a Project > Clicking More Options > View as Hiring Manager.
In order to see a project, users need to be added as Team Members. Review Project Permissions here.
Recruiters have this capability because it’s very common for recruiters to show aspects of their work to hiring managers. This permission allows a recruiter to impersonate a hiring manager and preview the page before sharing, ensuring they do not share any sensitive data or work in progress.
When considering whether you should grant this permission to a custom role, it’s important to understand that users with the Impersonate User permission can take actions on behalf of other users.
For example, if I were an Admin impersonating a Researcher, I would be able to add a new person to the talent database and add them to a project. This action would appear as though the Researcher completed both actions.
The impersonated user will receive an email notification for any actions that occur from users impersonating them.
How to Add a New User
As an Admin, once you know which role you’d like your team member to assume, you can invite new users into the system and assign them a role in the Admin Portal.
To get there, navigate to the lower-left, hover your click until the side-bar menu appears. Click Go To Admin Portal, click on Users at the top of the menu on the left, and navigate to the + User button on the upper right.
There, you can fill in the name and email of the team member you’d like to invite, and select the appropriate role that corresponds to the permissions you’d like to assign.
How to Change a User's Role
In the Admin section, click the Users tab from the left-hand side navigation.
Find the user you wish to update using the search filter.
Click
to the right of the user's name and click Edit Details.Choose the new role from the Role dropdown menu.
Click Save to apply the changes.
FAQ
As an admin, should I invite new users into Thrive first or configure all role types before inviting my team?
We recommend you configure all role types before inviting your team members into the system as users. Read about System Roles and decide if you need to adjust any of the pre-set permissions. If so, build and save a Custom Role. Once you’ve taken these steps, it’s a quick process to assign a user the desired role.
Help! I assigned someone the wrong role. How do I fix it?
Don’t worry, we’ve made it easy to re-assign a user role. Here’s how:
1. Navigate to the Admin Portal > Users
2. Search for the user you need to edit
3. Click on the ellipses (the three dots on the far right)
4. Click Edit Details
5. Select the correct user role from the drop-down (if you need to review your roles and permissions
Which permissions cause issues when they aren’t enabled?
Not having view access to people prevents users from adding notes, scorecards, events, and outreaches
Not having view access to Scorecard templates can be challenging because you won’t be able to see the names of scorecard templates your team has previously created. This requires you to know the exact name of the Scorecard template you want to add to the project to ensure you’re adding the correct one
Ability to create/view/edit the following associations
I am looking at a person, and I can't see the notes or scorecards tab at all. What permission do I need?
Ask your administrator for permission to view people.
I can't create references, referrals, connections, documents or events for a person. What permission do I need?
Ask your administrator for permission to edit people.
Are there any permissions I should restrict for my team?
We recommend caution when enabling the Impersonate User permission, delete capabilities (currently unavailable to all users, including admins), compensation data, and potentially viewing custom fields if there is sensitive information captured that should not be visible to all team members.




