Every gated action in Leed names a privilege. Before the action runs, Leed compares the privilege’s minimum role against your base role, and — if that fails — against any access override you hold on the resource in play. This page is the complete list of those privileges, plus the role-by-role summary most people actually come here for. If you have not met the six roles themselves yet, start with Roles and Permissions; this page assumes them.
Privileges are plan-independent. Nothing on this page changes when you change tier.
How to read this table
Roles are cumulative, so minimum role means that role and every stronger one. A privilege whose minimum is Content Writer is satisfied by Content Writer, Content Approver, Content Publisher and Administrator alike.
An override on a page type, a label or a page satisfies these same checks — see Resource-Level Access Overrides for the stronger-of rule, which is the only place the two systems meet.
And when a check fails, the 403 body names the privilege verbatim:
Unauthorized: missing page:publishSo the fastest route through this page is to search it for the string in the error you are holding.
All 58 privileges
Groups are the product’s own; the order below is the order they are declared in.
| Group | Privilege | Minimum role | What it gates | Enforced? |
|---|---|---|---|---|
| Page | page:read | Read Only | Viewing a page and its content | ✓ |
| Page | page:write | Content Writer | Editing a page’s content and metadata, including moving it into the APPROVED state | ✓ |
| Page | page:approve | Content Approver | Nothing — declared for page approval and never checked | † |
| Page | page:create | Content Publisher | Creating a page, including creating one from Markdown | ✓ |
| Page | page:publish | Content Publisher | Publishing, scheduling, revising, reverting and deleting a page | ✓ |
| Label | label:read | Read Only | Viewing labels and their members | ✓ |
| Label | label:write | Content Publisher | Creating and editing labels | ✓ |
| Label | label:publish | Content Publisher | Nothing — labels reach the site through the deployment flow | † |
| Page Types | pagetype:read | Read Only | Viewing page types | ✓ |
| Page Types | pagetype:write | Content Writer | Editing a page type and its configuration | ✓ |
| Page Types | pagetype:publish | Content Publisher | Nothing — page types reach the site through the deployment flow | † |
| Billing | billing:write | Administrator | The Billing and plan settings screen and every billing action | ✓ |
| Settings | settings:read | Read Only | Nothing — each settings area is gated by its own privilege instead | † |
| Settings | settings:write | Administrator | Nothing — each settings area is gated by its own privilege instead | † |
| User | user:read | Read Only | Reading one member and their overrides; also gates the Team members card in Settings | ✓ |
| User | user:write | Content Publisher | Editing another member’s profile, role and site profile fields; writing access overrides | ✓ |
| User | user:create | Administrator | Inviting a member, and creating one directly through the API | ✓ |
| User | user:delete | Administrator | Removing a member from the workspace | ✓ |
| User | user:publish | Content Publisher | Nothing — the member list is published through the deployment flow | † |
| RBAC | rbac:read | Read Only | Reading the “what can I do here” capabilities payload | ✓ |
| RBAC | rbac:write | Content Publisher | The role dropdown and the Billing/Developer checkboxes on Team Members, and the override editors on Labels and Page Types — in the interface only | ‡ |
| Asset | asset:read | Read Only | Viewing the asset library and individual assets | ✓ |
| Asset | asset:update | Content Writer | Changing an existing asset’s metadata or file | ✓ |
| Asset | asset:create | Content Writer | Uploading a new asset | ✓ |
| Asset | asset:delete | Content Publisher | Deleting an asset | ✓ |
| Company | company:read | Read Only | Viewing the company profile and General settings | ✓ |
| Company | company:write | Content Publisher | Editing the company profile and site-wide settings | ✓ |
| Company | company:publish | Content Publisher | Nothing — company settings reach the site through the deployment flow | † |
| Journey | journey:read | Read Only | Viewing journey stages | ✓ |
| Journey | journey:write | Content Publisher | Creating and editing journey stages | ✓ |
| Journey | journey:publish | Content Publisher | Nothing | † |
| Developer | developer:write | Content Publisher | Every developer surface — the developer settings entry point and eleven backend routes behind it | ✓ |
| Contact | contact:read | Read Only | Reading contacts, leads and email records | ✓ |
| Contact | contact:write | Content Publisher | Creating and editing contacts, lead batches and emails | ✓ |
| Contact | contact:publish | Content Publisher | Sending contact-facing work live, including campaign deliverable approval | ✓ |
| Contact | contact:delete | Content Publisher | Deleting contacts | ✓ |
| AI | ai:write | Content Writer | AI authoring actions that write content | ✓ |
| Analytics | analytics:read | Read Only | The Know dashboard and the analytics endpoints behind it | ✓ |
| Menu | menu:read | Read Only | Viewing menus, including the documentation left navigation | ✓ |
| Menu | menu:write | Content Writer | Editing a menu draft | ✓ |
| Menu | menu:publish | Content Publisher | Publishing a menu | ✓ |
| Notifications | notifications:read | Read Only | Nothing — notifications are not permission-gated | † |
| Path | path:read | Read Only | Viewing URL paths and redirects | ✓ |
| Path | path:write | Content Writer | Creating and editing a path or redirect | ✓ |
| Path | path:delete | Content Writer | Deleting a path or redirect | ✓ |
| Form | form:read | Read Only | Viewing forms and their submissions | ✓ |
| Form | form:write | Content Writer | Creating and editing a form | ✓ |
| Form | form:publish | Content Publisher | Nothing — forms reach the site through the deployment flow | † |
| Autolinks | autolinks:read | Read Only | Viewing auto-linking rules | ✓ |
| Autolinks | autolinks:write | Content Writer | Creating and editing auto-linking rules | ✓ |
| Dynamic CTAs | dynamiccta:read | Read Only | Viewing dynamic CTAs and recommendation settings | ✓ |
| Dynamic CTAs | dynamiccta:write | Content Writer | Creating and editing a dynamic CTA | ✓ |
| Dynamic CTAs | dynamiccta:publish | Content Publisher | Publishing a dynamic CTA | ✓ |
| Deployments | deployment:read | Read Only | Viewing the Deploy screen and deployment history | ✓ |
| Deployments | deployment:publish | Content Publisher | Starting a publish | ✓ |
| Deployments | deployment:promote | Content Publisher | Promoting a preview deployment to live | ✓ |
| Shortcode | shortcode:read | Read Only | Viewing short URLs | ✓ |
| Shortcode | shortcode:publish | Content Publisher | Creating a short URL | ✓ |
✓ enforced — this privilege is checked somewhere in the product. † defined but never checked; see the next section. ‡ checked in the interface only; the server gates the same actions on user:write.
Privileges that exist but are never checked
Ten of the fifty-eight are declared with a minimum role and then never consulted. They are not secretly enforcing anything, and a member who “lacks” one of them will never see a 403 naming it.
| Privilege | Minimum role it claims | What actually gates the action |
|---|---|---|
page:approve | Content Approver | page:write (Content Writer) — the APPROVED state is set through the ordinary page update |
label:publish | Content Publisher | The deployment flow: deployment:publish (Content Publisher) |
pagetype:publish | Content Publisher | The deployment flow: deployment:publish (Content Publisher) |
settings:read | Read Only | Each settings card carries its own read privilege — company:read, user:read, label:read, and so on |
settings:write | Administrator | Each settings area carries its own write privilege — company:write, user:write, and so on |
user:publish | Content Publisher | The deployment flow: deployment:publish (Content Publisher) |
company:publish | Content Publisher | The deployment flow: deployment:publish (Content Publisher) |
journey:publish | Content Publisher | Nothing separate — journey stages are saved under journey:write |
notifications:read | Read Only | Nothing — notification reads are not permission-gated |
form:publish | Content Publisher | The deployment flow: deployment:publish (Content Publisher) |
There is an eleventh case, of a different kind. rbac:write is a front-end gate only. It disables five controls across three screens: the role dropdown and the Billing and Developer checkboxes on Settings → Team Members, and the access-override editors on Settings → Labels and Settings → Page Types. The server does not check it at all: changing a role or writing an override is gated on user:write, and creating a page-type or label override is additionally entitlement-gated on contentRbac — removing one is not. rbac:write and user:write share a minimum role of Content Publisher, so a reader gets the same answer either way, but an integrator reading the API will never find rbac:write in a response, an error or a route. It is also the first thing to check when the Content Manager, Approver and Contributor pickers described in Resource-Level Access Overrides are visible but inert: that is this gate, not an expired plan.
What each role can do
The table below is built from routes that are actually enforced. Read a row as: this role can do this if its column says so.
| Capability (route-verified) | Minimum role | Administrator | Content Publisher | Content Approver | Content Writer | Read Only | Restricted |
|---|---|---|---|---|---|---|---|
| View pages | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | override only |
| Edit page content and metadata | Content Writer | ✓ | ✓ | ✓ | ✓ | — | override only |
| Create a page | Content Publisher | ✓ | ✓ | — | — | — | — |
| Publish, schedule, revise, revert or delete a page | Content Publisher | ✓ | ✓ | — | — | — | override only |
| View page types | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | override only |
| Edit a page type | Content Writer | ✓ | ✓ | ✓ | ✓ | — | override only |
| View labels | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | override only |
| Create and edit labels | Content Publisher | ✓ | ✓ | — | — | — | override only |
| View team members ※ | ungated | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Read one member and their overrides | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Edit another member’s profile or role | Content Publisher | ✓ | ✓ | — | — | — | — |
| Edit your own profile | yourself | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create a member (API only) | Administrator | ✓ | — | — | — | — | — |
| Remove a member | Administrator | ✓ | — | — | — | — | — |
| Create or delete an access override | Content Publisher | ✓ | ✓ | — | — | — | — |
| Read access overrides | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | override only |
| Billing settings | Administrator | ✓ | — | — | — | — | billing override |
| Developer settings | Content Publisher | ✓ | ✓ | — | — | — | developer override |
| View assets | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Upload and update assets | Content Writer | ✓ | ✓ | ✓ | ✓ | — | — |
| Delete an asset | Content Publisher | ✓ | ✓ | — | — | — | — |
| View deployments | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Publish and promote | Content Publisher | ✓ | ✓ | — | — | — | — |
| Edit menus, forms, paths, autolinks and dynamic CTAs | Content Writer | ✓ | ✓ | ✓ | ✓ | — | — |
| Read contacts and emails | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Write, approve or delete contacts and emails | Content Publisher | ✓ | ✓ | — | — | — | — |
| Edit the company profile | Content Publisher | ✓ | ✓ | — | — | — | — |
| AI authoring | Content Writer | ✓ | ✓ | ✓ | ✓ | — | — |
| Analytics | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| View short URLs | Read Only | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Create a short URL | Content Publisher | ✓ | ✓ | — | — | — | — |
※ The endpoint that lists members carries no permission check at all, so any signed-in member of the workspace can retrieve the list. The Team members card in Settings is gated on user:read, so a Restricted member has no way to reach the screen through navigation — but the data is not protected by a role.
“override only” means the base role does not satisfy the check, and an access override on the resource in play can. On the two settings rows it names the specific override: the Billing checkbox for billing, the Developer checkbox for developer. Billing and Developer Access covers those two, which are the only privileges you can grant with a checkbox.
Content Approver has no column entry that Content Writer lacks. That is not an omission in the table — it is the state of the product, and Roles and Permissions explains what the role is genuinely for.
Where the checks happen
A privilege is checked in two places, and they are not the same check.
On the server, a route declares rbacValidator("<privilege>") and the request is refused with a 403 if it fails. That is the enforcement, and nothing gets past it. In the interface, a control asks checkAuth({ privilege, resourceFilters }) and disables or hides itself. That is a courtesy, and it can be wrong in both directions.
It can be wrong by showing you a control you cannot use: the Delete item in a team member’s ⋮ menu is drawn for every viewer and fails server-side for anyone who is not an Administrator. And it can be wrong the other way, by hiding a screen from someone whose data is not actually protected — the member list is readable by any signed-in member even though the card that links to it is gated. Whether a screen appears at all is a separate question from whether its data is protected, and it is answered in Who Can See What.
An AI client can ask for a machine-readable version of exactly this table, resolved for the signed-in user — role, every privilege with its minimum role and whether it is granted, and the overrides that apply. See MCP Tools: Analytics and Introspection for how to call it. Note what it cannot do: those tools read permissions and never grant them.