Privacy and analytics

We use necessary technical cookies and, only with your consent, analytics and marketing pixels to improve the website and measure campaigns.

Privacy policyCookie policy
Docs
English
EspañolEnglishFrançaisDeutschItaliano

Getting started

  • What is Nömad?
  • Getting started with Nömad
  • Create your brand and complete the Genome
  • Invite your team
  • Glossary

Brand OS

  • What is inside Brand OS
  • What is the Genome?
  • Who is Nödo?
  • What does a Brand Manager do?
  • Brand Kit and Library
  • Posts and calendar
  • Connections
  • Meetings

Work

  • Work and tasks
  • Ordering work
  • Following, reviewing and approving deliveries
  • Custom quotes
  • Yes, there are humans behind it

Account and billing

  • Plans and pricing
  • Billing and payments
  • Roles and permissions
  • Workspaces and multiple brands
  • Languages, apps and data

Help

  • How to get help

API

  • Brand API
    • Permissions and roles
    • Brand
    • Genome
    • Brand Kit
    • Library
    • Works
    • Calendar
    • Connections
    • Publishing
    • Inbox
    • Team
    • Conversation
    • Memory
    • Questions
    • Media
    • Store
    • Plan
    • Orders
    • Activity

MCP

  • MCP server

Connectors

  • Brand connectors

Nödo and agents

  • Nödo in the brand
API/Brand API
Concept1 min read

Permissions and roles

How the gate decides who can do what in each brand.

On this page
  • Brand roles
  • Minimum role per area
  • Scopes

Updated on January 1, 1970

Previous
Português
Русский
한국어
日本語
中文
हिन्दी
Open the app
Brand API
NextBrand

In this section

  • Brand
  • Genome
  • Brand Kit
  • Library
  • Works
  • Calendar
  • Connections
  • Publishing
Can't find what you need? Write to usWrite to usGo to the app
© 2026 Nömad · Nömad documentationLinkedInInstagramFacebookTikTokYouTubeX
Go to nomad.oooBack to top

On this page

  • Brand roles
  • Minimum role per area
  • Scopes

Every call goes through the same gate, whether it comes from Nödo, an external agent or a key. The gate answers four questions in this order.

  1. Who is it? A person (session, Nödo acting for them, OAuth or personal key).
  2. What are they in this brand? Their effective role: workspace owner, all-brands access, per-brand access or direct member; the highest role wins. Nömad staff enter through their permission and brand assignment.
  3. What were they granted? The scope of the key or OAuth consent. Nödo inside the app has no scope limit: it uses the full role of the person speaking.
  4. Is the brand operational? A closed or archived brand only accepts reads.

Brand roles

RoleWhat it can do
OwnerEverything, including deleting the brand.
AdminEverything except deleting the brand.
MemberView and create content, works and calendar; view the Kit.
ViewerView content, Kit and calendar.
BillingView plan, billing, orders and subscriptions.

Minimum role per area

AreaReadWrite
BrandViewerAdmin
GenomeViewerMember
Brand KitViewerAdmin
LibraryViewerAdmin
WorksViewerMember
CalendarViewerMember
ConnectionsAdminAdmin
PublishingViewerMember
InboxViewerViewer
TeamViewerMember
ConversationViewerRead-only
MemoryViewerMember
QuestionsViewerMember
Media—Member
StoreViewerRead-only
PlanBillingRead-only
OrdersBillingRead-only
ActivityViewerRead-only

Scopes

Scopes are per area and kind: <area>.read and <area>.write. Ask only for what you need; when one is missing, insufficient_scope names it.

brand.read
brand.write
genome.read
genome.write
kit.read
kit.write
library.read
library.write
works.read
works.write
calendar.read
calendar.write
connections.read
connections.write
publishing.read
publishing.write
inbox.read
inbox.write
team.read
team.write
conversation.read
memory.read
memory.write
questions.read
questions.write
media.write
store.read
subscriptions.read
orders.read
activity.read