> ## Documentation Index
> Fetch the complete documentation index at: https://docs.langdock.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and extra permissions

> Compose workspace access from system roles, custom roles, and extra permissions so people can use products without becoming admins.

<iframe src="https://www.youtube.com/embed/y01bkN3M5uU" title="Roles and extra permissions overview" frameBorder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerPolicy="strict-origin-when-cross-origin" allowFullScreen style={{width: "100%", aspectRatio: "16 / 9"}} />

Compose access from a system role, optional custom roles, and optional extra permissions. People who keep their current role are unchanged. Admin always has every permission.

<Info>
  This page is available to workspace admins.
</Info>

## System roles

Member, Editor, and Admin come with the workspace and cannot be deleted.

* Member: default access for daily work
* Editor: create and share most products, without workspace settings
* Admin: every permission, including workspace settings and user management

In your workspace settings under **User management**, open [**Roles**](https://app.langdock.com/settings/workspace/user-management/roles).

Open a role to see permissions grouped by area, and turn on only what that role should include. Editing a role updates everyone who has it. Admin always has every permission and cannot be reduced.

The permission catalog is on [Permission Recommendations](/en/admin/workspace/permissions).

## Creating custom roles

You can also configure custom roles when several people need the same extra access. You can create up to 5.

Use it when a few people should create agents and share templates without becoming admins. Name the role something like "Champion", then assign it [on Members](#assigning-a-user-a-role-or-extra-permissions). If usage gets too high, turn that permission off on the role. Everyone with the role loses it at once.

<Steps>
  <Step title="Open Create role">
    On [**Roles**](https://app.langdock.com/settings/workspace/user-management/roles), under **Custom roles**, click **Create role**. The **Create a custom role** dialog opens.

    <Frame>
      <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_custom_roles.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=55d28318337d70dbcd1826a912f5ce26" alt="Roles settings with system roles listed and a Create role button in the Custom roles section" style={{borderRadius: '6px'}} width="1840" height="1506" data-path="images/roles_custom_roles.png" />
    </Frame>
  </Step>

  <Step title="Start from a role">
    Choose **Start from** Member or Editor so the new role copies those permissions. Enter a **Name**, add a **Description** if you want, then click **Create role**.

    <Frame>
      <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_create_role_dialog.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=4fee3bf9a7dae51aac21d3b002db57f2" alt="Create a custom role dialog with Name set to Champion, a description, and Start from Editor" style={{borderRadius: '6px'}} width="1840" height="1412" data-path="images/roles_create_role_dialog.png" />
    </Frame>
  </Step>

  <Step title="Turn permissions on">
    On the role page, turn on the permissions this role should have.

    <Frame>
      <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_champion_permissions.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=2710a414173c175762e3a795bcc7b3f8" alt="Champion custom role page with permissions grouped by area and toggles for agents, workflows, and templates" style={{borderRadius: '6px'}} width="1840" height="1780" data-path="images/roles_champion_permissions.png" />
    </Frame>
  </Step>
</Steps>

## Group permissions

You can also configure extra permissions at a group level, so that people in a group can, for example, get product access without needing to become workspace admins. Groups also have their own roles that are different from the system roles of your workspace.

To configure group permissions in your workspace, open [**Groups**](https://app.langdock.com/settings/workspace/user-management/groups) in your workspace settings.

### Group roles

A group role only applies inside that group. It does not change the workspace role.

* Group Members can use resources shared with the group
* Group Editors can share resources with the group
* Group Admins can do that, and they can add people and change group roles to Member or Editor

A Group Admin is not a workspace admin.

### Group admin

A Group Admin manages the group. They are not a workspace admin. They cannot change workspace system roles, create custom roles, or turn products on or off for the workspace. Only a workspace admin can assign the Group Admin role.

From the start, a Group Admin can:

* Share resources with the group
* Add and remove people
* Change group roles to Member or Editor
* Change the group name and description
* Delete the group

With **Grant extra permissions to group members**, they can also:

* Grant extra permissions to people in that group, such as **Create agents** or **Share templates**
* Grant only to people in the group. After that, the user can use the access across the workspace

If a row already comes from the user's workspace role, it shows **Already from their workspace role**. If several people need the same extras, use a [custom role](#creating-custom-roles) instead.

A workspace admin can also turn on **View governance** for a Group Admin. That user can then open [Governance](/en/admin/governance/overview), but only for work that belongs to people in the group, such as their agents. Adding people to the group, or sharing the group with them, does not give them Governance.

## Assigning roles and extra permissions

### Assigning a user a role or extra permissions

On [**Members**](https://app.langdock.com/settings/workspace/user-management/members), click the user's role. The **Edit access** drawer opens.

<Frame>
  <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_edit_access.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=b37fac4481327e1dbe1e9970b9b3915c" alt="Edit access drawer for Max Weber with Member selected, Champion custom role checked, and extra permissions expanded by area" style={{borderRadius: '6px'}} width="1840" height="2286" data-path="images/roles_edit_access.png" />
</Frame>

Keep one of Member, Editor, or Admin. You can also assign the custom roles that exist in the workspace. The workspace can have up to 5 custom roles.

**Extra permissions** add access for this user on top of their roles. If you make them Admin, custom roles and extra permissions are removed. Admin already includes every permission.

Click **Save** when you are done.

### Making a user a Group Admin

On [**Groups**](https://app.langdock.com/settings/workspace/user-management/groups), open the group. Set that user to Admin in the group. Their workspace role can stay Member or Editor. Only a workspace admin can assign the Group Admin role.

<Frame>
  <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_group_members.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=69e5f4178fc3920b09283650e75c5e9f" alt="AI enablement group with Anna Schmidt and Max Weber as group Admin and Lena Fischer as Member" style={{borderRadius: '6px'}} width="1840" height="1136" data-path="images/roles_group_members.png" />
</Frame>

### Turning on extra permissions for Group Admins

On [**Groups**](https://app.langdock.com/settings/workspace/user-management/groups), open that Group Admin. Turn on **Grant extra permissions to group members**. They do not become a workspace admin.

<Frame>
  <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_group_leader.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=1fe562a478024d07e2bda5db1620fc84" alt="Group access for Max Weber in AI enablement with group role Admin and Grant extra permissions to group members turned on" style={{borderRadius: '6px'}} width="1840" height="2286" data-path="images/roles_group_leader.png" />
</Frame>

### Granting extra permissions in a group

On [**Groups**](https://app.langdock.com/settings/workspace/user-management/groups), if **Grant extra permissions to group members** is on, open a user in the group. Under **Extra permissions**, turn on what they should have. They can use that access across the workspace.

<Frame>
  <img src="https://mintcdn.com/langdock-34/rxigIzv5_CMOOtWq/images/roles_group_leader_grant.png?fit=max&auto=format&n=rxigIzv5_CMOOtWq&q=85&s=cdb4bfa7a8f0d90c04e7c34e8ad679ba" alt="Group drawer for Lena Fischer with Extra permissions open, the workspace-wide grant hint, and Create agents available" style={{borderRadius: '6px'}} width="1840" height="2286" data-path="images/roles_group_leader_grant.png" />
</Frame>
