Skip to main content
Roles bundle permissions so you can give groups of users consistent access. Open Settings > Roles to review the available roles. System roles display a System badge. You can inspect their permissions, but you cannot rename, edit, or delete them. Role creation, management, and deletion require their respective Create, Manage, and Delete permissions under Roles.

Create a role

1

Start a new role

Select New role.
2

Name the role

Enter a concise Role name that describes the job the person performs.
3

Select permissions

Expand each permission group and select only the actions the role needs. Selecting a group selects all permissions in that group.
4

Create the role

Review the permission count, then select Create role.
The new role becomes available in the role selector on the Users page.

Edit a custom role

  1. Select the role from the list.
  2. Change the Role name or permission selections.
  3. Select Save changes.
  4. Review users assigned to the role when the change affects access.
The role list shows how many permission groups and individual permissions are enabled. Use that summary to spot roles with unexpectedly broad access.

Delete a custom role

  1. Reassign members who still use the role.
  2. Select the role.
  3. Select Delete role in the toolbar or Danger zone.
  4. Review the warning, then select Delete role.
Deletion cannot be undone. The current role editor tells you to review assigned members after deletion, so reassign them before you confirm.

Apply least privilege

  • Create roles around a job function, not a specific person.
  • Separate user administration from SSO, integrations, and data access when different teams own those systems.
  • Review custom roles when responsibilities change.
  • Keep feature-specific access disabled until the workspace has that feature.
See Permissions for the current permission catalog.
Last modified on September 16, 2026