Custom roles and the permission matrix
The role decides who can do what in the diary: a role carries permissions (log an event, issue a task, report…), and each colleague has a role. Alongside the built-in roles you can create a custom role, and in the permission matrix toggle each action on or off per role.
Before you start
Section titled “Before you start”- Permission: the role-management right — tenant_role:manage.
- Where to find it: the Roles and Permissions tabs in the management area.
Create a custom role
Section titled “Create a custom role”
- On the Roles tab, in the New custom role block, enter the Display name (e.g. Senior operator).
- Give a Key — a machine identifier (e.g. senior_operator).
- Choose a Base (inherited rights) — an existing role whose rights the new one starts from.
- Click Create role.
Set the permissions (permission matrix)
Section titled “Set the permissions (permission matrix)”On the Permissions tab there is a matrix: “One role per row, one action per column — the toggle sets the tenant-level right.” Turning a cell on gives the role that action; off removes it.
- Open the Permissions tab.
- Find the role’s row and the action’s column (if it is not obvious what a column allows, hover its header — it explains).
- Toggle the cell on/off. The change takes effect immediately.
If it worked
Section titled “If it worked”The new role appears in the roles list and is selectable at invitation time. Changes in the matrix take effect immediately: the toggle state decides what the role can do.
Common problems
Section titled “Common problems”| What you see | Why | What to do |
|---|---|---|
| No “Roles”/“Permissions” tab | You do not have the tenant_role:manage (or permission-management) right. |
Ask your admin. |
| I cannot change the Administrator’s row | Their rights cannot be restricted (locked). | Give the colleague a different role on the Users tab. |
| I do not know what a column allows | The action name is short. | Hover the column header — it shows the explanation. |
Related
Section titled “Related”Invite a colleagueYou assign the role at invitation time.
Edit the diary elementsHow the diary is built — governed by the roles' permissions.