Custom roles
Define Enterprise least-privilege roles and assign them safely.
A custom role lets an Enterprise organization replace a member’s broad built-in access with a focused permission set. Only the owner can manage roles on the Roles screen. A role needs a name that is not reserved and at least one permission. You can assign a role only through the member-management flow. Reserved names are owner, admin, and member. An organization can have at most 50 custom roles.
You need Enterprise access to create, edit, delete, assign, or unassign a custom role. If the workspace downgrades from Enterprise, existing role assignments still apply. Access does not expand. You cannot make these changes until Enterprise access returns. You must unassign a role from every member before you can delete it. This requirement stops an accidental fallback to a broader built-in role.
Treat a role change as production access control. Review the intended permissions. Make sure that an owner makes the change. Make sure that the member’s resulting access in the affected dashboard surface is correct. Use Members to invite members and manage their lifecycle. Use the REST roles guide only for trusted backend automation. This guide has stricter API-key requirements.