Open Settings → Roles to inspect the permissions granted by each role. The list separates roles shipped with the workspace from custom roles and shows how many holders each role has. Select a role name or View permissions to open its permission details.

Shipped workspace roles, including the protected Account Manager role and their assigned member counts.
Shipped roles provide the starting permission profiles; protected roles have additional restrictions. Open full-size screenshot.

Understand combined access

A member can hold several roles. Their grants combine: a role with less access does not cancel a broader grant from another role. To reduce access, review every assigned role as well as any record-specific collaboration rights.

Workspace ownership and the protected Account Manager role carry broad administrative access. Some operations, including ownership transfer, have additional restrictions. API and MCP also require their own approvals and access settings; a role alone does not enable either service.

Read permission levels

LevelPurpose
No accessThis role grants no access to the capability. Another role or an explicit collaboration grant may still provide access.
ReadRead records available within the applicable workspace and record rules.
Edit own recordsCreate and manage records within the capability's supported own-record scope.
Edit all recordsBroad read, create, update and delete permissions for the capability, subject to its workflow and record rules.

Edit own records appears only where supported. Ownership, creation and explicit participation can have different meanings across modules; follow the relevant module's access rules. Workspace-wide settings and reference configuration do not have a personal record scope.

Approval requirements, record state and workspace capabilities still apply. An edit grant does not automatically approve a policy version, bypass a demand review or make an unavailable integration ready.

Risk Manager role details showing full edit access to Risk Management and no access to the other displayed modules.
Open a role to inspect its permission levels before assigning it. Open full-size screenshot.

Create a custom role

  1. Choose New role.
  2. Give it a clear name and a short description of the responsibility it supports.
  3. Review every capability. New roles begin with No access.
  4. Select the appropriate level for each required capability.
  5. Choose Save changes and verify the role in the catalogue.
  6. Assign it through Settings → Members or the invitation form.

Creating a role does not assign it to anyone. Editing an assigned custom role changes what its holders can do as soon as the save succeeds. Cancel an unsaved editor to leave the definition unchanged.

The current role catalogue exposes editing and deletion for custom roles. Inspect shipped and protected roles through their permission details; use a custom role when a different permission set is needed. A custom role cannot be deleted while a member or invitation still uses it.

Unsaved Compliance Reviewer role with a description and No access selected for its displayed module permissions.
A new custom role begins with no access. Set the intended module permissions before saving. Open full-size screenshot.

Databases Management governs Controls and Threats reference libraries. Catalog Management governs configuration vocabulary. Profile Management concerns the workspace's business context. Prompt Management and Integration Management govern those respective modules.

Policy Confidential Details controls access to the policy assurance layer in addition to policy content permissions. Review the policy guide when defining an employee reader role, and use an appropriate restricted location for information requiring stronger separation.

Workflow responsibilities are configured separately. For example, Risk demands selects roles for analyst and assurance duties. Define the workspace role first, assign suitable members, then configure the workflow gate.

Review roles after job changes and periodically during the programme. A familiar role name is not a substitute for checking its actual permission details.