stylehub.cloud

Custom roles and folder access

On this page

A custom role is a name you choose and a list of the 11 permissions it carries. Use one when Admin, Editor and Viewer do not fit.

Custom roles are part of Business

The plan overview lists them as Custom roles with fine grained rights. The built in roles are on every plan. See What each plan includes and Roles and what each one may do.

Building a role

WhereDashboard, Team, New role

You need team:manage, which is Change roles and remove members. The owner and admins have it.

  1. Open Team (opens in a new tab) and press New role beside the Roles heading.
  2. Give it a name of at most 40 characters. The button stays disabled until there is one. Two roles in the same brand cannot share a name, and a role belongs to the brand it was built in.
  3. Pick a starting point under Start from. Each button fills the list with what that built in role can do. Nothing clears the list. Everything stays editable afterwards.
  4. Tick and untick permissions. The foot of the dialog counts what you have chosen, and says This role can do nothing yet. while the list is empty.
  5. Press Create role. A name already in use is refused with A role with this name already exists.

What each starting point fills in

Start fromPermissions it fills in
Admin11 of 11
Editor7 of 11
Viewer3 of 11

The permissions you can hand over

The builder shows them in 4 groups.

The brand manual
Reading it, changing it, and putting it in front of the public.
Files
The asset library, its folders and its trash.
The team
Who else is in this brand and what they may do.
The workspace
Settings that apply to the whole brand.
GroupPermissionWhat it allows
The brand manualmanual:readView the brand manual
The brand manualmanual:writeEdit sections and content
The brand manualmanual:publishPublish and unpublish
Filesasset:readView assets
Filesasset:writeUpload files, and rename, edit, duplicate and refile them
Filesasset:deleteMove files to the trash and empty it
Filesasset:foldersMake and change folders and categories, upload a whole folder, and set who may use each one
The teamteam:readSee team members
The teamteam:inviteInvite new members
The teamteam:manageChange roles and remove members
The workspaceorg:settingsEdit workspace settings and domains

One permission is always added

A role saved without manual:read gets it anyway, so unticking View the brand manual never produces a member who can see nothing. Everybody in a brand can read the manual.

Two permissions you cannot grant

These belong to the owner alone, so the builder does not offer them.

PermissionWhat it would allow
org:billingManage billing and plan
org:deleteDelete the workspace

Billing and deleting the brand stay with one person. Handing the brand to somebody else is a transfer, not a permission: see Handing a brand over.

Putting somebody on a role

  • When you invite them. Your custom roles appear beside Admin, Editor and Viewer in the role field of the invite form. See Inviting people.
  • Afterwards. The role menu beside a member on Team (opens in a new tab) lists your roles under Custom, below the Built in ones.
  • Not your own seat. Changing your own role is refused.
  • Not the owner. The owner's seat cannot be moved to another role.

If a custom role is deleted before an invitation is accepted, the person still joins, as Viewer. Anybody with team:manage can put them on another role afterwards.

Changing a role, and deleting one

Edit role on the role's card opens the same dialog, filled with what the role holds today. Save role applies the change to everybody on that role at once.

Delete role asks first, and says how many people hold it. Everybody on a deleted role becomes a Viewer, who can see but not change anything. The card also shows the member count, or Nobody has this role.

A downgrade parks roles, and remembers them

When a plan change puts a brand over its members limit, seats past the limit are set to read only and the role they held is remembered. An upgrade gives it back. A custom role deleted in the meantime is not restored: the seat comes back on the built in role it was parked with. See What a downgrade freezes.

Folder access levels

WhereDashboard, Assets, a folder's menu, Rename and settings

A folder carries three settings, each naming the lowest role allowed to do that one thing.

Can see
Whether the folder and its files appear at all. Default: Everyone.
Can upload
Whether files may be added to it. Default: Editors.
Can delete
Whether files may be removed from it. Default: Editors.

Each setting offers the same 4 levels, and each applies to that role and above.

SettingWho that means
EveryoneViewer and above
EditorsEditor and above
AdminsAdmin and above
The ownerOwner and above

Changing these needs asset:folders, which is Make and change folders and categories, upload a whole folder, and set who may use each one. A folder whose Can see is anything other than Everyone is marked restricted under its name in the library.

Two gates, not one

A permission says what somebody may do anywhere in the brand. A folder setting says where they may do it. Uploading into one folder needs both: the asset:write permission, and a level that meets that folder's Can upload.

Folders inside restricted folders

A folder answers to the strictest setting above it. A child of an admins only folder is admins only whatever its own setting says, so a subfolder is never a way around the restriction above it. The dialog says it this way: Each setting applies to that role and above. Nested folders inherit the strictest setting of their parents.

Folders nest up to 4 levels deep. A move that would push a folder past that depth is refused. See Folders, categories and tags.

Where a custom role lands against a folder

A custom role is measured by what it can do.

A member whoCounts as
is the ownerOwner
has team:manage or org:settingsAdmin
has asset:write or asset:deleteEditor
has none of thoseViewer

What a restricted folder keeps out of

  • The library. A folder above somebody's level is not listed and its files are not shown.
  • The zip download. Files they may not see are left out of the archive rather than the download being refused.
  • The Export (opens in a new tab) page, which leaves out the same files.
  • Uploading, which checks both the Can see and the Can upload level of the folder.

Pages are gated too. Team (opens in a new tab) needs team:read. Somebody without it lands back on the dashboard. Every built in role has it.

Three roles worth copying

Photographer
Start from Editor, then untick everything but the file permissions and manual:read. Pair it with folders whose Can upload is Editors so they can fill the photography folder and nothing else.
Reviewer
Start from Viewer and add nothing. They read the manual and comment on it, because leaving a comment needs only manual:read. See Comments on a block.
Agency
Start from Editor and untick manual:publish. They build everything and somebody in house presses publish. See Reviewing changes before they go live.

Still stuck? Write to hello@stylehub.cloud and say which page you were on.

Custom roles and folder access - Stylehub