> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.scriptation.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# What are the roles and permissions in Scriptation Enterprise?

|| 📝 NOTE: This article applies to [Scriptation Enterprise](https://help.scriptation.com/en/article/what-is-scriptation-enterprise-tdmis7/) — the subscription tier for studios managing devices, permissions, and onboarding at scale. The free and [Industry Pro](https://help.scriptation.com/en/article/what-is-scriptation-industry-pro-1jfjecg/) consumer tiers don't include a web-based Admin Portal.

Scriptation Enterprise uses two related models to manage access: a **role hierarchy** that determines who can administer what, and a **permissions hierarchy** that determines what users can do inside Scriptation on their devices. Once you understand both, the procedural articles in this category will read much more clearly.

### The role hierarchy

Enterprise has four levels of access, from highest to lowest:

* **Enterprise Admin** — manages everything in the Enterprise. Can create productions, invite Production Admins, set Enterprise-wide permissions, override any production or device permission, and remotely deactivate any device.
* **Production Admin** — manages a single production (or several productions) they've been explicitly assigned to. Can invite users, set production-level permissions, and deactivate devices within their production(s). Production Admins can't see other productions or the Enterprise Admin tab.
* **User** — a person who's been invited to a production. Uses Scriptation on their device(s) to do their actual job (acting, directing, script supervision, etc.). Doesn't see the Admin Portal.
* **Device** — a single iPad, iPhone, or Mac running Scriptation under the user's Enterprise account. Devices are the unit Scriptation tracks and licenses.

A user can have multiple devices on one production. A device can only be on one production at a time.

### The permissions hierarchy

Permissions control what users can *do* inside Scriptation — for example, whether they can export annotations, share files, or access specific cloud connections. Permissions stack at three levels, with the more specific level overriding the more general one:

1. **Enterprise permissions** apply by default to every production and every device in the Enterprise. Enterprise Admins set these.
2. **Production permissions** override the Enterprise defaults for a single production. Either an Enterprise Admin or that production's Production Admin can set these.
3. **Device permissions** override both Enterprise and Production permissions for a single device. Enterprise Admins set these.

When you change a permission, the change is **forced down** to every device in scope. Affected devices will be required to restart Scriptation before the new permission takes effect.

##### Example

Suppose Enterprise permissions allow exporting annotations. A specific production handling pre-release material disables exporting via Production permissions. One actor on that production is approved to export their own annotations for an accessibility reason — an Enterprise Admin can set a Device override on that one device to re-enable exporting.

The override hierarchy in plain English: the smaller scope wins.

### Where you set each level

| Level | Who sets it | Where in the portal |
| ---- |
| Enterprise | Enterprise Admin | Productions tab → **Permissions** in the upper bar |
| Production | Enterprise Admin or Production Admin | Productions tab → click a production → **Permissions** |
| Device | Enterprise Admin | Productions tab → click a production → device row's **⋯** menu → **Permissions** |

For step-by-step instructions, see [How do I set permissions on Scriptation Enterprise?](https://help.scriptation.com/en/article/how-do-i-set-permissions-on-scriptation-enterprise-1xrp3r5/) and [How do I override device permissions on Scriptation Enterprise?](https://help.scriptation.com/en/article/how-do-i-override-device-permissions-on-scriptation-enterprise-r1ji3g/).

||| ⚠️ HEADS UP: Any permission change forces a restart of Scriptation on every device in scope. Users see a prompt to restart the app — they can't continue working until they do.

# What's Next

[How do I set permissions on Scriptation Enterprise?](https://help.scriptation.com/en/article/how-do-i-set-permissions-on-scriptation-enterprise-1xrp3r5/)
[How do I override device permissions on Scriptation Enterprise?](https://help.scriptation.com/en/article/how-do-i-override-device-permissions-on-scriptation-enterprise-r1ji3g/)
[How do I add a Production Admin to my Enterprise?](https://help.scriptation.com/en/article/how-do-i-add-a-production-admin-to-my-enterprise-1k5vcax/)
[Tour of the Enterprise Admin Portal](https://help.scriptation.com/en/article/tour-of-the-enterprise-admin-portal-1o697ye/)