Help centre · Setup
Roles
What each role can do, described by the specific actions it carries (a capability) rather than by a page it can open — so "can this person issue a credit note" has one real answer, not a guess from what is in their sidebar.
When you would use this: your five built-in ranks (Owner, Admin, Member, Contractor, Viewer) do not fit — a bookkeeper who should issue invoices but never see payroll-adjacent settings, a coordinator who manages projects but not money.
Building one: a name, a description, a base rank (which only decides where the new role sits for navigation and who may edit it later, nothing else), and then the capability grid itself — every capability your product offers, grouped by area, each one a checkbox.
What you can grant: only what you yourself hold. The rank picker only offers your own rank and everything below it; a capability you do not have is not merely disabled in the grid, it is left out of what a role you create can carry at all — the server re-checks both the moment you save, whatever the form shows.
Holders: the count on each row links to the Staff directory filtered to the people currently on that role.
What happens next: change a role's capabilities and everyone holding it is affected immediately — nobody needs to sign out and back in.
When it refuses: no Roles item in your menu, or the screen itself refusing you, means you lack the permission to manage roles — by default only Owner and Admin hold it. A capability you try to grant that you do not hold yourself is rejected even if you found a way to check its box.