> ## Documentation Index
> Fetch the complete documentation index at: https://help.nextmatter.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom roles

> Create a workspace role with only the access a job needs, then assign it to a colleague or through SCIM.

<Info>
  Custom roles are available for customers on the Enterprise plan.
</Info>

A custom role is a named set of workspace permissions for one job. Use one when **Admin** is broader than the work someone should do. A user admin, for example, can manage colleagues and teams while workflow building, integrations, and workspace settings stay with someone else.

Each person has one workspace role. The built-in roles are **Admin**, **Member**, and **Light user**. Assigning a custom role makes that role their workspace role.

Team membership and **Team lead** are set on the team, in [Company > Teams](/docs/build-teams). What someone can do with a specific workflow still follows [folder and workflow visibility](/docs/about-visibility-and-permissions), workflow lead, and step assignment. A custom role adds workspace-wide access on top of that.

## Built-in roles

Built-in roles are the same in every workspace. Open one from **Company > Roles** to see what it includes. The **Type** column shows **Built-in**, and the permissions on that role stay fixed.

| Role | What it's for |
| - | - |
| **Admin** | Full access to workflows and workspace settings, including colleagues, teams, and integrations. |
| **Member** | Access to public workflows and to workflows they've been invited to. |
| **Light user** | Access to portals, the inbox, and the workflows shared through portals. |

Use a built-in role when it already matches the job. Create a custom role for a smaller or different set. For the task-by-task breakdown of the built-in roles, see [Team permissions](/docs/team-permissions).

## How the permission screen is organized

Permissions on the role page are grouped into the same areas as the product:

* **General**
* **Home**
* **Workflows**
* **Portals**
* **Roadmap**
* **Data tables**
* **Data**
* **Automations Library**
* **Workspace**

Each area shows a checkbox and a count of how many of its permissions are selected, in the form **3 of 10 selected**. Select the area checkbox to include every permission in that area, or select individual permissions under it. Each permission has a short description of what it allows.

Where a permission depends on another, the page draws that relationship as a tree. The dependent permission sits under the one it needs. Selecting it also selects everything it requires, including a required permission in another area. Clearing a permission also clears every permission that depends on it.

The permissions in each area change as Next Matter adds capabilities. The names and descriptions on this screen are the reference for what each permission does.

<Tip>
  In **General**, one permission controls whether this person can be chosen as a team lead, workflow lead, tech lead, or workflow editor. Select it when the job includes being assigned one of those roles.
</Tip>

## Create a user admin role

This walkthrough creates a **User admin** role that can manage colleagues and teams, with the other product areas left out.

1. Go to [Company > Roles](https://app.nextmatter.com/app/workspace/roles).
2. Click **+ Create role**.
3. In **Role name**, enter `User admin`.
4. In **Description**, say what the role is for. For example, `Manages colleagues and teams`.
5. Under **Workspace**, select the colleagues permissions and the teams permissions:
   * Permissions that show the **Colleagues** page and manage colleagues (invite, edit, and remove people, and assign their role).
   * Permissions that show the **Teams** page, view every team, create teams, and manage team membership.
6. In that same **Workspace** area, leave out of office, API keys, **Settings**, and managing roles unselected. Managing roles is the permission that creates, edits, and deletes custom roles.
7. Leave **General**, **Home**, **Workflows**, **Portals**, **Roadmap**, **Data tables**, **Data**, and **Automations Library** unselected.
8. Click **Create role**.

Next Matter also selects the permissions the tree shows those choices depend on, including the permission that opens the **Company** section.

<Info>
  Managing colleagues includes assigning a workspace role. Someone with this **User admin** role can give a colleague **Admin**, **Member**, **Light user**, or another custom role. Leave **managing roles** unselected when a different person should be the one who defines which roles exist.
</Info>

<Tip>
  Assign the new role to one person first. Ask them to open **Company** and confirm they can manage colleagues and teams, and that **Workflows**, **Automations library**, and **Settings** are unavailable. Tasks already assigned to them still show in the **Inbox**.
</Tip>

A custom role exists in the workspace where you create it. Create it again in each workspace that needs the same role.

## Assign the role to a user

1. Go to [Company > Colleagues](https://app.nextmatter.com/app/workspace/colleagues).
2. In the **Role** column, open the menu for that person.
3. Under **Custom roles**, select **User admin**.

The menu lists **System roles** first (**Admin**, **Member**, and **Light user**), then **Custom roles**. Each custom role shows the description you entered.

The role menu is unavailable on your own row. Ask another admin to change your role. The workspace always keeps at least one **Admin**.

To assign the role while inviting someone, click **+ Add colleague**, enter their details, and select **User admin** under **Custom roles** in **Role**. Then click **Send invitations**.

## Assign the role with SCIM

Custom roles can be assigned automatically with [SCIM](/docs/SCIM).

Create the role in Next Matter first, so your identity provider can offer it. Then assign that custom role the same way you assign a built-in Next Matter role. The next sync applies it, and **Company > Colleagues** shows the custom role in the **Role** column.

For a user provisioned through SCIM, that role is read-only in Next Matter. Hover the role and the tooltip reads **Managed by your identity provider — change this user's role there instead.** Change the role in the identity provider. When the identity provider sends a built-in role, or sends no role, the next sync follows that update. A user with no role from SCIM is still assigned **Light user**. See [Roles and teams](/docs/SCIM#roles-and-teams).

## Update or delete a role

1. Go to [Company > Roles](https://app.nextmatter.com/app/workspace/roles).
2. Click the custom role's name, or click the edit icon on its row.
3. Change the name, the description, or the selected permissions.
4. Click **Save changes**.

The update applies immediately to everyone who already has that role. Use the search field on the **Roles** page to find a role by name.

To delete a role, click **...** on its row and select **Delete role**. Next Matter deletes a role only when nobody is assigned to it. Move those people to another role first. Deleting a role can't be undone. Built-in roles stay in the list.

## Keep the role list easy to run

* Name the role for the job, such as `User admin` or `Integration owner`, and use the description so the next admin can see what the role is for.
* Start with the smallest set of permissions that job needs. Add a permission when someone is blocked, and clear one when the job no longer needs it.
* Keep one role per job. When someone changes jobs, change the role on their row in **Company > Colleagues**. Editing the role itself changes it for everyone who has it.
* Review custom roles when an admin joins or a team's work changes, so a role keeps only the access that job still needs.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.