Users and Roles
Who this is for
Section titled “Who this is for”Users with Settings manage permission. System Manager role changes require a System Manager, even if another manager can administer ordinary roles.
Before you start
Section titled “Before you start”Map the person’s real responsibilities to module actions and access level. Do not create a role solely to bypass an owner-scope restriction without reviewing the broader impact.
- Open Settings → Roles & Permissions and inspect the existing role hierarchy and permission rows.
- Create a custom role with a distinct display name and only the modules/actions it needs. Write permissions automatically imply read access in the stored role definition.
- Assign or revise roles through the approved team/role management workflow; confirm any System Manager role change with a System Manager.
- To delete a custom role, open the delete dialog, review the affected user count, select a replacement role when users still hold it, and type the exact role name to confirm.
What happens next
Section titled “What happens next”Role changes invalidate authorization caches and write an audit event after the main mutation succeeds. System roles cannot be deleted.
Troubleshooting
Section titled “Troubleshooting”- Duplicate role name: display names are unique case-insensitively.
- Role cannot be deleted: reassign all assigned users first or choose a replacement in the dialog.
- A user still cannot act: check their resolved permission union and the target record’s owner scope.
