A Role is a named bundle of permissions you assign to one or more users, rather than setting access person-by-person. This guide covers creating a role, understanding the two levels of granularity available for each resource type, and reading a role's access at a glance.
Before you begin#
- Access to Settings → Roles.
- A sense of which resource types (positions, connections, workflows, and so on) the role actually needs to touch, and at what level.
Create a role#
- Open Settings → Roles and select Create Role.
- Enter a Name and an optional Description.
- Save.
A new role starts with zero permissions: nothing is granted until you add it.
Choose general or granular access#
For each resource type, a role's permissions page offers two cards:
- All {Resource}s: permissions here apply to every resource of that type, including ones created after this role was set up. Use this when the role should have blanket access to a whole category, such as every connection.
- Specific {Resource}s: grants access to individual resources only, letting you scope a role down to particular positions, connections, or workflows rather than the whole category.
The two cards don't offer the same ceiling. All {Resource}s offers No access, Read, Update, or Delete, plus separate toggles for Can create new {resource}s and Can execute all {resource}s where those actions apply (the execute toggle requires Read to also be selected). Specific {Resource}s tops out lower: No access, Read, or Update for most resource types, plus an additional Execute column for Workflows and Cuelists. Delete can only be granted through All {Resource}s: there's no way to grant delete access to one specific resource without granting it for every resource of that type.
Read a role's access at a glance#
The Roles list shows each role's granted resource types as icon badges. Hovering a badge summarizes what it actually grants: for example, "Full access to all {resource}s" for complete access, or a narrower summary like "Can read and update some {resource}s" when access is partial or scoped to specific items rather than the whole category.
If you get stuck#
What you see | What to try |
|---|
A new role doesn't let its users do anything yet. | That's expected: a new role starts with zero permissions. Add the specific resource-type grants it needs. |
You're not sure whether a role affects future resources too. | Check whether its permission is set on the All {Resource}s card (applies to new resources automatically) or Specific {Resource}s (scoped to what's explicitly listed, not automatic for new ones). |
A user with a role still can't perform an action. | Confirm the role grants at least the right access level (Read/Update/Delete) for that resource type, and, if scoped to specific resources, that the resource in question is actually included. |
You want a quick summary of what a role can do. | Hover its resource-type badges on the Roles list rather than opening each permission individually. |
Where to go next#