Role Creation¶
Custom roles let you model your organization's hierarchy without forcing users into predefined buckets. You can create roles from scratch or clone an existing role as a template.
Who this is for¶
Admin Executive
Prerequisites¶
- Tenant Admin or Super Admin role
- Review of Role Management Overview
- Defined permission requirements for the new role
Create a role from scratch¶
- Go to Admin > Role Management.
- Click New Role.
- Enter a Role Name and optional Description.
- Select a Base Tier: Standard, Advanced, or Admin.
- Choose the initial Permissions from the checklist.
- Click Save.
Clone a role¶
Cloning copies all permissions and settings from an existing role. This is the fastest way to create variations.
- Go to Admin > Role Management.
- Find the role you want to clone.
- Click the ... menu and select Clone.
- Enter a new Role Name.
- Adjust permissions as needed.
- Click Save.
Clone default roles
Clone default roles such as Analyst or Editor to create department-specific variants without starting from zero.
Permission checklist¶
When creating a role, you select permissions across these categories:
- User Management: Invite, deactivate, delete
- Role Management: Create, edit, assign
- Configuration: Workflows, fields, branding, notifications
- Security: SSO, MFA, audit logs
- Records: Create, read, update, delete, approve
- Reports: View, export, schedule
- Integrations: Configure, test, disable
Step-by-step: create a department-specific role¶
- Click New Role.
- Name it "Finance Analyst."
- Clone from the base Analyst role.
- Add the View Audit Logs permission with scope Own Records Only.
- Remove the Delete Records permission.
- Click Save and Assign Users.
Permissions required¶
| Role | Permission | Scope |
|---|---|---|
| Super Admin | Create and clone roles | Organization |
| Tenant Admin | Create and clone roles | Organization |
| Content Admin | View role details | Organization |
| Analyst | Cannot create roles | — |
| Viewer | Cannot create roles | — |
Limits and guardrails¶
Limit Role names must be unique within the tenant.
Limit A role can have up to 200 permissions.
Limit Custom roles cannot exceed the base tier of the creator. Only Super Admin can create roles with Admin tier.
Troubleshooting¶
Issue: cloned role has unexpected access
Cause: The source role contained hidden group permissions or custom conditions. Resolution: Review the cloned role in Permission Assignment and remove unwanted rules.
Issue: role not visible to assign to users
Cause: The role is saved but not published, or it belongs to a tier higher than the assigning admin. Resolution: Ensure the role status is Active. Confirm the admin's tier supports assigning that role.
Related pages¶
Escalation path¶
For role creation failures or tier conflicts:
- Verify your admin tier in My Account > Profile.
- Check the role creation audit log for error details.
- File a support ticket with the intended role name and permissions.
- Escalate to
#valuepact-opsif the UI returns a persistent error.