Custom roles and folder access
On this page
A custom role is a name you choose and a list of the 11 permissions it carries. Use one when Admin, Editor and Viewer do not fit.
Custom roles are part of Business
Building a role
WhereDashboard, Team, New role
You need team:manage, which is Change roles and remove members. The owner and admins have it.
- Open Team (opens in a new tab) and press New role beside the Roles heading.
- Give it a name of at most 40 characters. The button stays disabled until there is one. Two roles in the same brand cannot share a name, and a role belongs to the brand it was built in.
- Pick a starting point under Start from. Each button fills the list with what that built in role can do. Nothing clears the list. Everything stays editable afterwards.
- Tick and untick permissions. The foot of the dialog counts what you have chosen, and says This role can do nothing yet. while the list is empty.
- Press Create role. A name already in use is refused with A role with this name already exists.
What each starting point fills in
| Start from | Permissions it fills in |
|---|---|
| Admin | 11 of 11 |
| Editor | 7 of 11 |
| Viewer | 3 of 11 |
The permissions you can hand over
The builder shows them in 4 groups.
| Group | Permission | What it allows |
|---|---|---|
| The brand manual | manual:read | View the brand manual |
| The brand manual | manual:write | Edit sections and content |
| The brand manual | manual:publish | Publish and unpublish |
| Files | asset:read | View assets |
| Files | asset:write | Upload files, and rename, edit, duplicate and refile them |
| Files | asset:delete | Move files to the trash and empty it |
| Files | asset:folders | Make and change folders and categories, upload a whole folder, and set who may use each one |
| The team | team:read | See team members |
| The team | team:invite | Invite new members |
| The team | team:manage | Change roles and remove members |
| The workspace | org:settings | Edit workspace settings and domains |
One permission is always added
manual:read gets it anyway, so unticking View the brand manual never produces a member who can see nothing. Everybody in a brand can read the manual.Two permissions you cannot grant
These belong to the owner alone, so the builder does not offer them.
| Permission | What it would allow |
|---|---|
org:billing | Manage billing and plan |
org:delete | Delete the workspace |
Billing and deleting the brand stay with one person. Handing the brand to somebody else is a transfer, not a permission: see Handing a brand over.
Putting somebody on a role
- When you invite them. Your custom roles appear beside Admin, Editor and Viewer in the role field of the invite form. See Inviting people.
- Afterwards. The role menu beside a member on Team (opens in a new tab) lists your roles under Custom, below the Built in ones.
- Not your own seat. Changing your own role is refused.
- Not the owner. The owner's seat cannot be moved to another role.
If a custom role is deleted before an invitation is accepted, the person still joins, as Viewer. Anybody with team:manage can put them on another role afterwards.
Changing a role, and deleting one
Edit role on the role's card opens the same dialog, filled with what the role holds today. Save role applies the change to everybody on that role at once.
Delete role asks first, and says how many people hold it. Everybody on a deleted role becomes a Viewer, who can see but not change anything. The card also shows the member count, or Nobody has this role.
A downgrade parks roles, and remembers them
Folder access levels
WhereDashboard, Assets, a folder's menu, Rename and settings
A folder carries three settings, each naming the lowest role allowed to do that one thing.
Each setting offers the same 4 levels, and each applies to that role and above.
| Setting | Who that means |
|---|---|
| Everyone | Viewer and above |
| Editors | Editor and above |
| Admins | Admin and above |
| The owner | Owner and above |
Changing these needs asset:folders, which is Make and change folders and categories, upload a whole folder, and set who may use each one. A folder whose Can see is anything other than Everyone is marked restricted under its name in the library.
Two gates, not one
asset:write permission, and a level that meets that folder's Can upload.Folders inside restricted folders
A folder answers to the strictest setting above it. A child of an admins only folder is admins only whatever its own setting says, so a subfolder is never a way around the restriction above it. The dialog says it this way: Each setting applies to that role and above. Nested folders inherit the strictest setting of their parents.
Folders nest up to 4 levels deep. A move that would push a folder past that depth is refused. See Folders, categories and tags.
Where a custom role lands against a folder
A custom role is measured by what it can do.
| A member who | Counts as |
|---|---|
| is the owner | Owner |
has team:manage or org:settings | Admin |
has asset:write or asset:delete | Editor |
| has none of those | Viewer |
What a restricted folder keeps out of
- The library. A folder above somebody's level is not listed and its files are not shown.
- The zip download. Files they may not see are left out of the archive rather than the download being refused.
- The Export (opens in a new tab) page, which leaves out the same files.
- Uploading, which checks both the Can see and the Can upload level of the folder.
Pages are gated too. Team (opens in a new tab) needs team:read. Somebody without it lands back on the dashboard. Every built in role has it.
Three roles worth copying
manual:read. Pair it with folders whose Can upload is Editors so they can fill the photography folder and nothing else.manual:read. See Comments on a block.manual:publish. They build everything and somebody in house presses publish. See Reviewing changes before they go live.Still stuck? Write to hello@stylehub.cloud and say which page you were on.