How-to

Create a custom role

Create a custom role by giving it a name that is unique in the business, ticking the permissions it should carry, and adding people to it. The built-in Admin role cannot be changed, so any narrower set of abilities needs a role of your own.

Create a custom role by giving it a name that is unique in the business, ticking the permissions it should carry, and adding people to it. The built-in Admin role cannot be changed, so any narrower set of abilities needs a role of your own.

Requirements

Steps

  1. Create the role. Give it a name and, optionally, a description. Name it for the job, not the person: Recruiter, Office Manager, Account Coordinator. The name must be unique within the business.
  2. Tick its permissions. Permissions are listed by category, such as automations or collections. Tick each one the role should carry. A role starts with nothing, so it can do only what you tick.
  3. Add people to it. Assign existing members to the role, or give it to new people when you invite a user.
  4. Check it as that person would. Walk through what the role needs to do day to day. If a task fails, the missing permission is the one that governs it.

How this fits the access model

A person gets abilities only through a role (elsewhere: user group, permission set), and a role only through its permissions. How access works covers that chain. Roles live inside one business and never carry into another.

Notes and limitations

  • Admin is fixed. The Admin role is created with the business. It cannot be renamed, its permissions cannot be changed, and it cannot be deleted.
  • Admin does not hold everything automatically. Admin carries every permission implicitly, except a few that must be granted on purpose even to administrators. Viewing every email message in the business is one of them.
  • Deleting a role. A custom role can be deleted only once no one is assigned to it. Move its people to another role first.
  • Renaming. A custom role's name and description can be changed at any time; its people and permissions stay as they are.

To decide which permissions a role needs, see Design a role: what permissions govern.

Frequently asked questions

Can I remove a permission from Admin?
No. Admin is a system role: its name and permissions are fixed. Create a custom role with the permissions you want instead.
Does Admin see everything?
Most, but not all. A few permissions, such as viewing every email message in the business, must be granted even to Admin.
Can I delete a role that people are using?
Only after everyone assigned to it has been moved to another role.