Access Control
Access control decides who can see what in Arketic AI. Your role, your department, and each document's access level work together so that you always see what you need and never see what you shouldn't.
This page explains, in plain terms, what controls what you can open, view, and do.
Your role decides what you can reach
Your role controls which menu items appear in your sidebar and which pages you can open. Everyone can use the day-to-day features, and higher roles unlock organization-wide views and management tools.
There are three roles you'll encounter as a user:
| Role | What it's for |
|---|---|
| Member | The standard employee role. Full access to your everyday tools — chat, assistants, projects, tasks, and your own documents. |
| Executive | An organization-wide read role. Sees the big picture across the organization, including dashboards, the knowledge base, analytics, and a read-only org chart. Cannot manage users, departments, workflows, or prompts. |
| Administrator | Full control of your organization's workspace, including managing people, departments, workflows, prompts, and AI assistant setup. |
For the complete breakdown, see Roles & Permissions.
Who can open what
| Area | Member | Executive | Administrator |
|---|---|---|---|
| Chat & conversations | Yes | Yes | Yes |
| Assistants | Yes | Yes | Yes |
| Projects | Yes | Yes | Yes |
| Tasks | Yes | Yes | Yes |
| My Documents | Yes | Yes | Yes |
| Profile | Yes | Yes | Yes |
| Dashboard | — | Yes | Yes |
| Knowledge Base | —* | Yes | Yes |
| Blueprints | —* | Yes | Yes |
| Org Chart | — | Read-only | Yes |
| Analytics | — | Yes | Yes |
| Workflows | — | — | Yes |
| Prompts | — | — | Yes |
| AI Assistants (builder) & Models & Providers | — | — | Yes |
| Organization (Departments, Users) | — | — | Yes |
| Help & Support | — | — | Yes |
* Members who manage a top-level department are the one exception — see below.
:::info Department managers get a little more If you're a member who manages a top-level department, you also get access to the Knowledge Base and Blueprints, even though you're not an administrator. This lets you look after your department's shared knowledge without needing full admin rights. :::
Direct links are protected too
Access control isn't just about hiding menu items. Arketic re-checks your role every time you open a page — including when you use your browser's Back button or refresh. If you type in (or follow a link to) the address of a page your role can't use, Arketic simply sends you back to your home page.
This means a page you can't see is genuinely off-limits, not just hidden. There's no "back door" through the address bar.
Document access levels
Every document has an access level that decides who can open it. There are five levels:
| Level | Who can see it |
|---|---|
| Personal | Only you. |
| Team | Your team members. |
| Department | Members of that department. |
| Organization | Everyone in your organization. |
| Confidential | Administrators and executives only. |
A member can never open another person's Personal document, and only administrators and executives can open Confidential documents — if a member tries, access is denied.
For how to set and change these levels, see Access Levels.
Department scoping
Beyond your role, some of what you see is scoped to your department:
- Tasks — You see tasks from your own department. If you manage one or more departments, you see those too. Administrators and executives can see tasks across the organization.
- AI document search — When the AI searches documents for you, it only surfaces documents you're actually allowed to open. It won't pull up confidential documents or documents from departments you don't have access to.
Access control follows you everywhere — including into your conversations with the AI. The assistant can only work with the documents your access level already allows.
Account security
Your account is protected from the moment you sign in.
| Protection | What it means for you |
|---|---|
| Password required | Every account needs a password of at least 8 characters. Use a strong, unique one. |
| Accounts created by admins | There's no self sign-up. If you need an account, an administrator creates it for you — the sign-in screen shows "Contact an Administrator." |
| Security question after failed sign-ins | After several failed sign-in attempts, you'll be asked to solve a quick security question (a simple math problem) before you can try again. |
| Temporary lockout | Too many failed attempts temporarily locks the account. The sign-in screen shows a countdown, and the lock lifts automatically once the wait is over. |
| Automatic session timeout | You stay signed in while you're actively using Arketic; after a period of inactivity your session expires and you'll need to sign in again. |
| Approval for sensitive AI actions | When the AI wants to take a real action for you — such as acting inside a connected app — a confirmation card appears with the details and Approve / Cancel buttons. Nothing happens until you approve. |
Signing out
To sign out, click your name at the bottom of the sidebar and choose Sign Out. Signing out ends your session immediately and clears cached data on that device, so your account can't be reopened without signing in again.
:::caution On a shared or public computer Always sign out when you're done. Because signing out clears cached data on that device, it's the best way to make sure the next person can't see your information. :::
Messages you might see at sign-in
If something goes wrong when signing in, Arketic tells you what happened:
| Message | What it means |
|---|---|
| "Invalid email or password. Please try again." | The email or password didn't match. Check both and retry. |
| "Your account is not active. Please contact your administrator." | Your account isn't active yet — an administrator needs to help. |
| "Your organization account has been suspended. Please contact support." | Your organization's account is suspended. |
| "Too many failed login attempts. Security verification required." | You'll need to answer the security question before trying again. |
| "Wrong answer. Please try again." | The security question answer was incorrect. |
| "Your account has been temporarily locked." | Wait for the countdown to finish, then try again. |
| "Cannot connect to server. Please check your connection." | A network issue — check your internet connection. |
Tips
- Never share your password with anyone, including colleagues.
- Sign out when using shared or public computers.
- Report suspicious activity to your administrator right away.
Related pages
- Roles & Permissions — the full role breakdown
- Access Levels — setting document access
- Data Privacy — how your data is kept safe