What user roles are available on Arino One?
Arino One has four user roles — Owner, Administrator, Supervisor and Agent — assigned per instance, with unlimited seats included under the flat $50/month connection fee. Role sets what a user can do; inbox assignment, set separately, sets what conversations they can see.
The permission matrix
| Capability | Owner | Admin | Supervisor | Agent |
|---|---|---|---|---|
| Billing and contracts | Yes | No | No | No |
| Instance settings | Yes | Yes | No | No |
| Channels and senders | Yes | Yes | No | No |
| Automations and templates | Yes | Yes | Request | No |
| Users and roles | Yes | Yes | No | No |
| Retention and erasure | Yes | Yes | No | No |
| Reporting | Yes | Yes | Yes | Own work |
| Inbox reply | Yes | Yes | Yes | Assigned inboxes |
Owner is typically held by one or two people responsible for the contract and instance as a whole. Administrator covers day-to-day configuration — channels, automations, users — without contract access. Supervisor is built for team leads who need full reporting and reply access but shouldn't change instance settings. Agent is the working role for anyone replying to customers day to day.
Role vs inbox visibility
Role and inbox visibility are two separate settings, and it's a common mistake to assume a role alone controls what an agent sees. An Agent's role grants reply and reporting rights scoped to "own work"; which conversations actually reach them is controlled by their inbox assignment, set in Account → Users → Inbox access. A support agent can be assigned only the general enquiries inbox, while a sales agent on the same Agent role is assigned only the sales inbox — neither sees the other's conversations, even though their role permissions are identical.
Supervisors and above see reporting across all inboxes by default, since their role already grants broader reporting rights; inbox assignment for them mainly controls where they can reply directly rather than what they can report on.
Unlimited seats
Seats are unlimited and included in the $50/month connection fee — there is no per-user charge, and adding a tenth or hundredth Agent does not change your platform subscription. This is separate from usage-based costs like messaging, voice or Ping Me, which scale with volume rather than headcount.
Quarterly review guidance
Review the full user list every quarter: confirm each person's role still matches their job, check inbox assignments still match their team, and remove anyone who has left the organisation. Keep a brief record of the review (who ran it, when, what changed) — this is exactly the kind of evidence a customer's security or procurement team will ask for, and it's far easier to produce from a habit than to reconstruct after the fact.
How this differs by connection status
| Connection status | Role administration |
|---|---|
| Connected ($50/month Arino Core connection) | Same four roles, managed by the client's Owner/Admins in the console; Arino can assist with role setup since the instance is connected |
| Unconnected | Same four roles exist in the template, but there is no Arino visibility or support for how they're assigned — the client's Owner is fully responsible |
The role model itself is identical regardless of connection status, since it's part of the underlying Arino One template. The difference is oversight: on a connected instance, Arino support can see role and inbox configuration if you raise a ticket, whereas on an unconnected instance there is no Arino connection, so role administration — and any mistakes in it — is entirely the client's own responsibility.
Next steps
Invite your first users and assign roles on the invite your team guide, and see how support responsibilities align with connection status on support and SLAs.
Frequently asked
What roles exist on an Arino One instance?
Four: Owner, Administrator, Supervisor and Agent, assigned per instance. Each carries a fixed set of permissions shown in the matrix on this page.
Do I pay per seat?
No. Seats are unlimited under the flat $50/month connection fee — adding users does not increase your platform subscription.
Does a role control what an agent can see, or only what they can do?
Role controls what an agent can do. What they can see in the inbox is set separately, by inbox assignment, so two agents with the same role can be scoped to entirely different conversations.
Who can change billing details?
Only the Owner role can view or change billing and contract details.
How often should roles be reviewed?
Quarterly. Review the full user list, confirm each person still needs their current role and inbox access, and remove anyone who has left — the review record is useful evidence in a security questionnaire.
Do roles differ by connection status?
The four roles and their permissions are the same whether or not the instance is connected. The difference is oversight: on a connected instance, Arino can assist with role setup; on an unconnected instance, there is no Arino oversight of how roles are assigned.
Apply this to your own deployment
This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.