Skip to content

Custom roles and the permission matrix

The role decides who can do what in the diary: a role carries permissions (log an event, issue a task, report…), and each colleague has a role. Alongside the built-in roles you can create a custom role, and in the permission matrix toggle each action on or off per role.

  • Permission: the role-management right — tenant_role:manage.
  • Where to find it: the Roles and Permissions tabs in the management area.
The New custom role form: display name, key (identifier, e.g. senior_operator), base (inherited rights) selector, and the Create role button.
The New custom role form. The base is an existing role whose rights the new one inherits — you refine from there in the permission matrix.
  1. On the Roles tab, in the New custom role block, enter the Display name (e.g. Senior operator).
  2. Give a Key — a machine identifier (e.g. senior_operator).
  3. Choose a Base (inherited rights) — an existing role whose rights the new one starts from.
  4. Click Create role.

On the Permissions tab there is a matrix: “One role per row, one action per column — the toggle sets the tenant-level right.” Turning a cell on gives the role that action; off removes it.

  1. Open the Permissions tab.
  2. Find the role’s row and the action’s column (if it is not obvious what a column allows, hover its header — it explains).
  3. Toggle the cell on/off. The change takes effect immediately.

The new role appears in the roles list and is selectable at invitation time. Changes in the matrix take effect immediately: the toggle state decides what the role can do.

What you see Why What to do
No “Roles”/“Permissions” tab You do not have the tenant_role:manage (or permission-management) right. Ask your admin.
I cannot change the Administrator’s row Their rights cannot be restricted (locked). Give the colleague a different role on the Users tab.
I do not know what a column allows The action name is short. Hover the column header — it shows the explanation.

Last updated: