Roles decide what someone sees and what they can change. This is what each one is for.
The six roles
These are Cloneable's own descriptions, which are the ones shown when you assign a role:
Org Admin. Top-level admin for the organization. Full access to organization settings, members, and configuration.
Workforce Manager. Manages people without full admin access. Sees every fielder's live location and all organization analytics, and can invite, edit, and deactivate members.
Team Admin. Can manage members and settings for their assigned team(s).
Analyst / Fielder. Recommended for most users. Can collect and manage data across all jobs without access to member or organization settings.
Analyst (Read-only). Can view all jobs, data objects, and poles across the organization, but cannot create, edit, or delete data and has no admin access.
Basic User. Can read and write their own data and view data shared within their team.
Analyst / Fielder is the one to reach for by default. It is the role for people doing the actual work, and Cloneable marks it as recommended when you are choosing.
Roles are not exclusive
Somebody can hold more than one role. So when you work out why somebody can, or cannot, do something you expected, check all of their roles rather than reasoning from one of them.
A menu is not a permission
What appears in somebody's menu and what they are actually able to do are worked out separately in Cloneable today, and they do not always agree.
The practical consequence for you, when assigning roles:
A missing menu item does not always mean the person is blocked from that area.
A visible menu item does not always mean they can do everything on it.
So do not assign a role and then verify it by looking at somebody's menu. If it matters that a person cannot do something, tell us what you try to achieve and we will confirm it properly rather than inferring it from a screen.
One concrete example worth knowing, because it looks like a fault: a read-only analyst loses the data section from their menu entirely, even though the role exists in order to let people view data.
After you change somebody's role
They do not need to sign out and back in. The change reaches their existing session.
If nothing seems to have happened, ask them to refresh the page first.
What you can hand out
A Workforce Manager cannot make somebody an Org Admin. Only an existing Org Admin can do that. So if you delegate people management but want to keep control of who holds the top role, Workforce Manager is exactly the right role to give.
Location, which is a setting rather than a role
Whether fielders appear on the map at all is an organization-wide setting rather than something carried by a role, and it is turned on or off once for everyone. See Your organization map for what it affects and Invite people, and set up teams for where to change it.
