Roles

Named permission sets: creating them, and designing a small number that actually fit.

1. Create a role

  1. Open the form

    Go to Settings → Team & access → Roles and press (+).

  2. Fill in the fields

    CampoObligatorioDescripción
    NameMaximum 255 characters — name it after the job, not the permissions.
    DescriptionNoWhat this role is for, so the next admin does not invent a duplicate.
    PermissionsNoAllowed actions per subject: read, create, edit, delete, approve, collect.
  3. Test with one person

    Assign it to one user and have them confirm they can do their job and nothing more.

2. Designing roles

  • Start from the jobs people actually do, not from the permission list.
  • Four or five roles is usually enough; twenty means nobody knows what any of them grant.
  • Grant the narrowest set that lets the job be done, then widen when something is genuinely blocked.

Changing a role changes access for everyone holding it. Before editing, check who that is — a small adjustment for one new hire can silently widen access for fifteen people.

Última actualización