Custom roles
|
INCLUDED IN This feature is included in our Enterprise plan, and available as a paid add-on in our Business plan. |
With custom roles, you can create tailored permission sets to better match your organization’s needs. This allows you to enhance security, streamline workflows, and ensure that users only have access to the features and data they need.
There are predefined roles that cannot be edited. These roles are locked (indicated by a padlock icon) and are designed to help you get started. With custom roles, you can go beyond these limitations and combine both account and workspace permissions into a single role.
Create a custom role
Create a unique role and tailor exactly which permissions it should include.
When creating a custom role, no permissions are enabled by default. You need to manually select all permissions you want the role to include.
- Go to Admin > Roles > click on "+ Create role"
- Name the role > click on the tab Permissions > Toggle on the permissions you want to activate > Confirm.
Permission labels
Each permission is marked with a label that indicates where it can be applied. These labels help you understand in which context the permission will take effect.
For example, a permissions with the label "Account" will not have an effect if applied on a workspace.
However, if you assign the same role at the account level, the user will be able to use that permission as intended.
| Account | Permissions with account labels can be applied at the account level (via Account access) |
| Workspace | Permissions with workspace labels can be applied only on workspace (via workspace access) |
| Account or Workspace | Can be applied at either level. |
Account or workspace access
Once you’ve created a custom role and selected its permissions, you need to assign it to a user or group and a resource, e.g. account or workspace
You can either grant access at the account level or limit access to specific workspaces.
If a role includes permissions labeled Workspace or Account and Workspace, and you assign that role at the account level, the user will gain access to all workspaces across the account with that role.
🔗 Click here to read more about how to grant access to account and workspaces