Roles & permissions
Data-driven RBAC enforced at the API.
Seven roles, two tiers
Built-in roles cover the organization and workspace tiers. The matrix under Settings → Roles shows exactly what each role can do; permissions are enforced server-side, never just hidden in the UI.
Custom roles
Define your own roles when the built-in seven don't match a job function: name the role, tick exactly the permissions it should carry, and save. Custom roles appear in the same matrix and in the Team role pickers, are enforced server-side like the built-ins, and can be edited any time (changes apply immediately). A role can't be deleted while it's still assigned; system roles stay read-only.
Just-in-time access
Grant a user a time-boxed, per-workspace role elevation that expires automatically — least privilege without standing access. Pick the user, the workspace, the role, and a duration; duplicates are blocked, every grant and revoke is audited, and the elevation takes effect in that workspace immediately.
Try it yourself
Open the console and put this into practice.