Disqovr

Create roles and manage permissions

Create least-privilege roles and understand how access is resolved.

#permissions#roles#custom role#access#least privilege#admin#member role#settings#integrations#security#create

Roles define broad workspace capabilities. Project membership, project visibility, groups, locations and task-specific assignments then narrow what a person can see or do in a particular context. Start with the least access needed and add responsibility deliberately.

In the app: /settings/permissions

Before you start

• Only workspace admins can create, edit or delete custom roles.

• List the real responsibilities of the role before selecting permissions; avoid cloning Admin as a shortcut.

Step by step

1. Review built-in and custom roles

Open Settings → Permissions and compare the existing roles. Built-in roles provide common baselines; custom roles are for a repeatable responsibility that does not fit them.

2. Create a clearly named role

Choose Create role, use a responsibility-based name and add a description that explains who should receive it.

3. Select only required capabilities

Enable the actions holders need for their job. Pay particular attention to administration, billing, workspace-wide vendor data and destructive actions.

4. Assign the role from Team

Open Team, select the member and apply the new role. A role definition has no effect until it is assigned.

5. Test with the real access model

Confirm the member can reach the intended workspace and project surfaces. Check project membership, visibility, groups and locations if access is still narrower than expected.

Treat billing, API, workspace deletion and member-management capabilities as high privilege.

What happens next

• Role changes take effect against the member’s next authorised request; a refresh or new session may be needed for the UI to update.

• Review custom roles during access reviews and before deleting a role that may still be assigned.

Troubleshooting

A member has the role but cannot open a project

Check the project visibility and membership as well as group or location scope. A workspace capability does not automatically grant every restricted project.

A permission change appears not to apply

Refresh the page or sign in again, then verify the member belongs to the active workspace rather than another tenant.

A custom role cannot be deleted

Reassign any members using it first. Built-in roles cannot be removed.

Related guides

Related articles

Still stuck? Contact us →