Custom roles are available for customers on the Enterprise plan.
Built-in roles
Built-in roles are the same in every workspace. Open one from Company > Roles to see what it includes. The Type column shows Built-in, and the permissions on that role stay fixed.
Use a built-in role when it already matches the job. Create a custom role for a smaller or different set. For the task-by-task breakdown of the built-in roles, see Team permissions.
How the permission screen is organized
Permissions on the role page are grouped into the same areas as the product:- General
- Home
- Workflows
- Portals
- Roadmap
- Data tables
- Data
- Automations Library
- Workspace
Create a user admin role
This walkthrough creates a User admin role that can manage colleagues and teams, with the other product areas left out.- Go to Company > Roles.
- Click + Create role.
- In Role name, enter
User admin. - In Description, say what the role is for. For example,
Manages colleagues and teams. - Under Workspace, select the colleagues permissions and the teams permissions:
- Permissions that show the Colleagues page and manage colleagues (invite, edit, and remove people, and assign their role).
- Permissions that show the Teams page, view every team, create teams, and manage team membership.
- In that same Workspace area, leave out of office, API keys, Settings, and managing roles unselected. Managing roles is the permission that creates, edits, and deletes custom roles.
- Leave General, Home, Workflows, Portals, Roadmap, Data tables, Data, and Automations Library unselected.
- Click Create role.
Managing colleagues includes assigning a workspace role. Someone with this User admin role can give a colleague Admin, Member, Light user, or another custom role. Leave managing roles unselected when a different person should be the one who defines which roles exist.
Assign the role to a user
- Go to Company > Colleagues.
- In the Role column, open the menu for that person.
- Under Custom roles, select User admin.
Assign the role with SCIM
Custom roles can be assigned automatically with SCIM. Create the role in Next Matter first, so your identity provider can offer it. Then assign that custom role the same way you assign a built-in Next Matter role. The next sync applies it, and Company > Colleagues shows the custom role in the Role column. For a user provisioned through SCIM, that role is read-only in Next Matter. Hover the role and the tooltip reads Managed by your identity provider — change this user’s role there instead. Change the role in the identity provider. When the identity provider sends a built-in role, or sends no role, the next sync follows that update. A user with no role from SCIM is still assigned Light user. See Roles and teams.Update or delete a role
- Go to Company > Roles.
- Click the custom role’s name, or click the edit icon on its row.
- Change the name, the description, or the selected permissions.
- Click Save changes.
Keep the role list easy to run
- Name the role for the job, such as
User adminorIntegration owner, and use the description so the next admin can see what the role is for. - Start with the smallest set of permissions that job needs. Add a permission when someone is blocked, and clear one when the job no longer needs it.
- Keep one role per job. When someone changes jobs, change the role on their row in Company > Colleagues. Editing the role itself changes it for everyone who has it.
- Review custom roles when an admin joins or a team’s work changes, so a role keeps only the access that job still needs.

