Custom roles
Define Enterprise least-privilege roles and assign them safely.
Custom roles let an Enterprise organization replace a member’s broad built-in access with a focused permission set. The Roles screen is owner-only for role management. A role needs a non-reserved name, at least one permission, and can be assigned only through the member-management flow. Reserved names include owner, admin, and member; an organization can have at most 50 custom roles.
Creating, editing, deleting, assigning, and unassigning custom roles all require Enterprise. If the workspace downgrades, existing assignments continue to enforce rather than silently expanding access, but mutation is frozen until Enterprise access returns. A role must be unassigned from every member before it can be deleted, which prevents an accidental fallback to a broader built-in role.
Treat a role change as production access control. Review the intended permissions, ensure an owner is making the change, and validate the member’s resulting access in the affected dashboard surface. Use Members for invitation and member lifecycle, and use the REST roles guide only for trusted backend automation with its stricter API-key requirements.