Roles and permissions
TrueTone has three roles: the loan officer, who owns their own content and settings; the org admin, who runs a company account and its seats; and TrueTone staff, an internal support role. Each role is limited to what it should reasonably touch, and every privileged action is recorded.
What it is
A role decides what a person can see and do. TrueTone keeps this deliberately small and predictable, so it is easy to reason about who has access to what.
There are exactly three roles:
- Loan officer. The everyday user. A loan officer owns their own content, voice, profile, website, contacts, and (on a personal plan) their own billing. This is the role almost everyone holds.
- Org admin. Runs a company account. An org admin manages the seats in their organization, distributes topics to the team, reviews content where that is enabled, and sees organization-wide analytics. Everything an org admin does is scoped to their own organization and no other.
- TrueTone staff. An internal support and operations role, held by TrueTone employees, not by customers. Staff can help across organizations when a customer needs support, and every step they take is governed and recorded.
There is no “member” role and no separate tier below loan officer. A person on a company account is called a seat, and a seat’s role is simply loan officer. A solo customer on a personal plan holds the same loan officer role; the only difference is that a company owns the shared settings for a seat, where a solo customer owns them for themselves.
Who it is for
Anyone who needs a plain answer to “who can access what.” Loan officers and org admins use this page to understand the boundaries of their own account. Sales, marketing, product, and support teammates use it to explain those boundaries to customers, and to reassure security-minded buyers that access is scoped and audited rather than open.
What each role can do
The table reads across: a loan officer sees only their own account, an org admin sees their whole organization, and TrueTone staff can reach across organizations to provide support.
| What it covers | Loan officer | Org admin | TrueTone staff |
|---|---|---|---|
| Their own content, voice, profile, and website | Yes | Yes | Yes |
| See another person’s account in the same company | No | Yes, within their organization | Yes, for support |
| Add, remove, or manage seats | No | Yes, within their organization | Yes, for support |
| Distribute seeds (topics) to the team | No | Yes | Yes |
| Review and approve team content, where enabled | No | Yes | Yes |
| Set per-seat spending limits | No | Yes | Yes |
| View organization analytics and reports | No | Yes, for their organization | Yes |
| Change organization settings, branding, and teams | No | Yes | Yes |
| Act on behalf of a loan officer | No | Within their organization only | Across organizations, for support |
| Reach into a different company’s data | No | No | Yes, for support, and always recorded |
An org admin’s reach stops at the edge of their own organization. There is no setting that lets one company’s admin see or touch another company’s seats, content, or analytics.
The roles in detail
Loan officer
The loan officer is the core role, and most people who use TrueTone are one. A loan officer controls everything that makes content sound and look like them: their TrueTone Profile and voice tuning, their voice model, their seeds and interests, the content they create across the five channels, their scheduling and social connections, their contacts, and their website.
A loan officer cannot see anyone else’s account, cannot administer an organization, and cannot act on another person’s behalf. On a personal plan they also own their own billing, branding, and organization details. On a company seat those shared settings belong to the company instead, but the loan officer’s own voice, writing, and content stay entirely theirs.
Who can act on whose behalf
In the mortgage industry it is normal for a marketing team to work on a loan officer’s behalf: posting to their social, updating their site, producing their content. TrueTone supports this properly through governed impersonation, where stepping into an account is a deliberate, recorded act rather than a free-for-all.
- A loan officer acts only as themselves.
- An org admin can act on behalf of loan officers in their own organization, and nowhere else.
- TrueTone staff can act on behalf of loan officers across organizations to provide support.
- Nobody acts on behalf of another admin or staff member.
Whenever someone works inside another person’s account, they choose view-only or act-on-behalf up front, give a real reason, and every action is attributed to the real person who took it. A short list of actions, around money, identity and security, and a loan officer’s cloned voice, stays off-limits even in act-on-behalf mode.
Acting on behalf of a loan officer is opted into every time, never the default. The full rules, and the record it produces, live on the Impersonation and audit page.
Keys and connectors are not a fourth role
An API key for the TrueTone API, or an AI assistant connected through the TrueTone Connector, does not get a role of its own. It acts as the person who created or approved it, and it never reaches past what that person could do themselves. Each key or connection is then narrowed further, to the Capability Groups chosen when it was granted, so a connection given only read access cannot create content even though its owner can. Ending the key or the connection ends the access. See API keys and AI connections.
Good to know
There is no “member” role. If you hear someone describe a company user as a “member,” they mean a seat, and a seat’s role is loan officer. Getting this right avoids confusion when talking to enterprise buyers.
On an enterprise account the organization is the billing entity, and each loan officer holds a seat under it. Adding a seat is an org admin action; the seat itself is a loan officer, with the same role and the same personal control over their own voice and content as any other loan officer.
Company data is isolated between organizations, and privileged actions are recorded to an audit trail. Access is scoped to a person’s role, and the record of who did what is kept whether the action was taken by an org admin or by TrueTone staff.