Tenants that set custom permissions on individual accounts hold those permissions as named roles on the Roles tab, described as "Legacy user role created for an existing user". The access is the same as before and no action is needed.
How It Works
Where to Find Them
Open Settings → Manage Users & Roles and go to the Roles tab. Legacy roles appear in the same list as the system roles and any custom roles your admins have built.
View role shows what the role grants, module by module.
What an Admin Can Do
A legacy role behaves like any other custom role. An admin can rename it, change its read and write grants, assign it to more users, duplicate it, or delete it once no users hold it.
A carried-over role is named after the account it came from, not the job it does. Rename it to match the job, and assign it to other users who need the same access.
Editing a role changes access for everyone holding it, so check who holds it first.
Supported Configurations and Options
Aspect | Detail |
Where they appear | The Roles tab under Settings → Manage Users & Roles |
Access granted | The same access the user already had |
Who can edit them | Admins, since the Roles tab is admin only |
Rename, edit, duplicate, assign | Yes, like any custom role |
Delete | Only once no users hold the role |
Action required | None |
Other Technical Specifications
Aspect | Detail |
Role model | A user holds one role, and a role can be assigned to any number of users |
Country and Global configuration | Read only for every custom role. Only admins can change it |
Billing & Payments | Cannot be granted to a custom role |
Notes
Legacy roles are not locked or special-cased in any way.
Where several legacy roles grant the same access, move those users onto one role and delete the rest.
Related Articles
Creating and Managing Custom Roles - building a role from scratch or from a duplicate
Types of Users and Their Roles - the five system roles and what each one covers

