Skip to main content
Roles listing page showing roles table with permissions

Overview

A role is a named set of permission rules that controls what a user can do on the platform. Every user is assigned exactly one role. Roles define permissions at the resource-and-action level — for example, “can create workflows” or “can read statistics.”
See the Permissions page for a complete explanation of how the permission system works, including resource scoping, team constraints, and the full permissions matrix.
Roles can also be decided by your identity provider — see automatic provisioning for the three ways a provisioned user gets a role.

Roles Listing

The Roles page displays all roles configured for your company: Use the search bar to find roles by name.

Creating a Role

1

Open the creation modal

Click Create role in the top-right corner.
2

Enter a role name

Choose a descriptive name that reflects the role’s purpose (e.g., “Marketing Editor”, “Data Analyst”, “Admin”).
3

Configure permissions

The permission editor displays a matrix of resources (rows) and actions (columns). Click a cell to cycle through its access levels — see Team scope per permission below.Use the All column at the start of a row to set every action of that resource at once.Only the actions that are applicable to each resource are shown. For example, Statistics only supports Access and Export, while Workflow supports Create, Read, Update, and Delete.See the Permissions Matrix for the full list of available combinations.
4

Create

Click Create to save the new role. Users assigned to this role will immediately receive the configured permissions.

Team Scope per Permission

Each cell of the matrix has up to three access levels. Clicking a cell moves to the next one. Edit role dialog showing the permissions matrix, with Datasource Read and Query set to own teams and their parent teams The Own teams and their parent teams level is only offered on team-scoped resources. Company-scoped resources such as User or Billing only switch between No access and Own teams.
This lets you open shared data without opening everything else. First, enable Exclude from ancestor inheritance on the brand team so its users stop seeing the parent market team’s resources. Then give the brand role Datasource → Read and Query with Own teams and their parent teams, keeping Workflow on Own teams: brand users get the market team’s Datasources but only their own Workflows.
Parent-team scope also applies to Create, Update and Delete when you select it on those actions. Users could then modify resources owned by teams above theirs. Prefer using it on Read and Query unless the role really needs to edit shared resources.
In the All column, a minus sign means the row mixes several levels. Clicking it resets the whole row to No access.

Synced Permissions

Some permissions are automatically kept in sync — you do not need to configure them separately: For example, granting “Create” on Content also grants “Create” on Content Font Resources. These synced permissions are not displayed in the role editor.

Built-in Rules

Every role automatically includes two rules that cannot be removed:
  • Read own profile — Every user can view their own user details.
  • Update own profile — Every user can edit their own name, password, 2FA settings, and preferences.
These rules only apply to the user themselves and do not grant access to other users’ profiles.

Editing a Role

  1. Click the actions menu (⋮) on a role row and select Edit.
  2. Update the role name or click cells in the matrix to change their access level.
  3. Click Save to apply.
Changes take effect immediately for all users assigned to this role. Review the impact before saving.

Deleting a Role

  1. Click the actions menu (⋮) and select Delete.
  2. A confirmation dialog warns that the action is irreversible.
  3. Click Delete to remove the role.
Deleting a role that is assigned to users will remove those permissions. Reassign affected users to another role before deleting.

Exporting Roles

Click the Export CSV button in the toolbar to download a CSV file containing all roles and their permission rules. The export includes: