Skip to main content
Compose access from a system role, optional custom roles, and optional extra permissions. People who keep their current role are unchanged. Admin always has every permission.
This page is available to workspace admins.

System roles

Member, Editor, and Admin come with the workspace and cannot be deleted.
  • Member: default access for daily work
  • Editor: create and share most products, without workspace settings
  • Admin: every permission, including workspace settings and user management
In your workspace settings under User management, open Roles. Open a role to see permissions grouped by area, and turn on only what that role should include. Editing a role updates everyone who has it. Admin always has every permission and cannot be reduced. The permission catalog is on Permission Recommendations.

Creating custom roles

You can also configure custom roles when several people need the same extra access. You can create up to 5. Use it when a few people should create agents and share templates without becoming admins. Name the role something like “Champion”, then assign it on Members. If usage gets too high, turn that permission off on the role. Everyone with the role loses it at once.
1

Open Create role

On Roles, under Custom roles, click Create role. The Create a custom role dialog opens.
2

Start from a role

Choose Start from Member or Editor so the new role copies those permissions. Enter a Name, add a Description if you want, then click Create role.
3

Turn permissions on

On the role page, turn on the permissions this role should have.

Group permissions

You can also configure extra permissions at a group level, so that people in a group can, for example, get product access without needing to become workspace admins. Groups also have their own roles that are different from the system roles of your workspace. To configure group permissions in your workspace, open Groups in your workspace settings.

Group roles

A group role only applies inside that group. It does not change the workspace role.
  • Group Members can use resources shared with the group
  • Group Editors can share resources with the group
  • Group Admins can do that, and they can add people and change group roles to Member or Editor
A Group Admin is not a workspace admin.

Group admin

A Group Admin manages the group. They are not a workspace admin. They cannot change workspace system roles, create custom roles, or turn products on or off for the workspace. Only a workspace admin can assign the Group Admin role. From the start, a Group Admin can:
  • Share resources with the group
  • Add and remove people
  • Change group roles to Member or Editor
  • Change the group name and description
  • Delete the group
With Grant extra permissions to group members, they can also:
  • Grant extra permissions to people in that group, such as Create agents or Share templates
  • Grant only to people in the group. After that, the user can use the access across the workspace
If a row already comes from the user’s workspace role, it shows Already from their workspace role. If several people need the same extras, use a custom role instead. A workspace admin can also turn on View governance for a Group Admin. That user can then open Governance, but only for work that belongs to people in the group, such as their agents. Adding people to the group, or sharing the group with them, does not give them Governance.

Assigning roles and extra permissions

Assigning a user a role or extra permissions

On Members, click the user’s role. The Edit access drawer opens.
Keep one of Member, Editor, or Admin. You can also assign the custom roles that exist in the workspace. The workspace can have up to 5 custom roles. Extra permissions add access for this user on top of their roles. If you make them Admin, custom roles and extra permissions are removed. Admin already includes every permission. Click Save when you are done.

Making a user a Group Admin

On Groups, open the group. Set that user to Admin in the group. Their workspace role can stay Member or Editor. Only a workspace admin can assign the Group Admin role.

Turning on extra permissions for Group Admins

On Groups, open that Group Admin. Turn on Grant extra permissions to group members. They do not become a workspace admin.

Granting extra permissions in a group

On Groups, if Grant extra permissions to group members is on, open a user in the group. Under Extra permissions, turn on what they should have. They can use that access across the workspace.