Skip to main content

Creating and Managing Custom Roles

The User Roles tab listing every role in the tenant, with Add New Role at the top right and view, duplicate, edit and delete actions on each row

A custom role is a named set of permissions you build yourself and assign to as many users as you like. Use one when none of the five system roles grants the right combination of modules for a job.

Custom roles are built on the Roles tab under Settings → Manage Users & Roles, using a grid of read and write checkboxes grouped by module. This guide is for admins.

Important: The Roles tab and the role builder are available to the Admin role only. Managers can add and edit users on the Users tab, but cannot create or change roles.


Prerequisites

  • The Admin role.

  • A clear idea of which modules the role needs, and whether each one should be view-only or editable.

  • For a role that needs the Trading Party tab of a configuration module, read access on Trading Parties, because that tab depends on it.


Steps

Creating a role

  1. Go to Settings → Manage Users & Roles and open the Roles tab. The tab lists the five system roles and any custom roles already in your tenant.

  2. Click Add role.

  3. Enter a name for the role. Choose something a colleague would recognize on the Users tab, such as "AP Team Lead" rather than "Custom 2".

  4. Optionally add a description explaining who the role is for. It shows next to the role on the Users tab role picker.

The role editor showing the role name and description fields above the permissions grid, with the Document actions group listing Review, Validate, Reprocess, Download and Delete, and the Manage Organizations group showing separate Read and Write columns

5. Work down the permission grid and set access module by module. Each module has a read checkbox and a write checkbox: - Read lets the role open the module and see what is in it. - Write lets the role change things. Turning on write automatically checks read and locks it, because you cannot edit something you cannot see. 6. Save the role.

Setting access on the four configuration modules

Instruction Builds, Transformations, Rejections and Customize Captured Fields each expand into four rows rather than one, matching the tabs inside the module:

Row

What it controls

Organization

The Organization tab of that module

Trading Party

The Trading Party tab of that module

Country

The Country tab of that module

Global

The Global tab of that module

Each row carries its own read and write checkboxes, so you can give a role write access to organization-level transformations while leaving country-level ones view-only.

Two constraints apply as you fill these rows in:

  • The Trading Party row stays greyed out, with an info note explaining why, until the role has read access on Trading Parties. Grant that first, and the row becomes available.

  • Country and Global rows offer read but not write. Country and Global configuration can only be changed by an admin, so a custom role can be given view access to those tabs and never edit access.

The Transformations, Rejections and Customize Captured Fields groups each expanded into Organization, Trading Party, Country and Global rows, where the Country and Global write boxes are greyed with the tooltip "Can only be edited by admins"

Note: Billing & Payments cannot be granted to a custom role at all. It stays with the Admin role.

Starting from an existing role

Rather than building a grid from scratch, duplicate a role that is already close to what you want:

  1. On the Roles tab, find the role you want to start from. This can be a system role or another custom role.

  2. Duplicate it. The new role opens with the same grants already selected.

  3. Rename it, adjust the description, and trim or extend the grid.

  4. Save.

Duplicating is also how you work from a system role, since system roles are read-only templates and cannot be edited in place.

Viewing, editing and deleting

  • View role opens a role and shows its grants. Use it on a system role to see exactly what that role covers before assigning it.

  • To change a custom role, open it, adjust the grid, and save. The change applies to every user holding that role.

  • To remove a custom role, delete it from the Roles tab. A role that is currently assigned to users cannot be deleted. Move those users to another role first, then delete it.

Assigning the role to users

  1. Open the Users tab.

  2. Add a new user, or edit an existing one.

  3. Pick your custom role from the role list, alongside the system roles.

  4. Save.


Expected Outcome

The role appears on the Roles tab and in the role list on the Users tab, ready to assign.

The Add new user dialog with the Role list open, showing Add New Role at the top followed by the built-in Docupath roles and their descriptions

Users holding it see only the modules their role can at least read. Inside those modules, anything the role cannot do is greyed out with the tooltip "You don't have permission to perform this action", so they can see what the module does without being able to act on it.


Common Issues

Issue

Cause

Resolution

The Roles tab is not there

The Roles tab is available to the Admin role only

Ask an admin to create or change the role. Managers can still add and edit users on the Users tab

The Trading Party row is greyed out

The role does not yet have read access on Trading Parties, which that row depends on

Grant read on Trading Parties, and the row becomes available

Write cannot be turned on for a Country or Global row

Country and Global configuration can only be changed by an admin, so write is never grantable on those rows

Grant read for visibility. If the person needs to edit those tabs, they need the Admin role

Read cannot be unchecked

Write is on, and write implies read

Turn off write first, then read becomes editable again

Billing & Payments is not in the grid

Billing & Payments cannot be granted to a custom role

Give the person the Admin role if they genuinely need billing access

A role cannot be deleted

The role is assigned to at least one user

Reassign those users to another role, then delete it

A user still cannot reach a module after the role was widened

The user signed in before the role was changed

Ask them to sign out and sign back in

A system role cannot be edited

System roles are read-only templates

Duplicate it and edit the copy


Notes

  • Write implies read. Turning on write auto-checks read and locks it, so a role can never have edit access to something it cannot see.

  • The four configuration modules expand into four rows each, one per tab, and each row carries independent read and write.

  • Country and Global configuration is view-only for custom roles. Only admins can change it.

  • Billing & Payments is outside the custom role grid entirely.

  • A role in use cannot be deleted, which keeps users from silently losing access.

  • Editing a role changes access for every user holding it, so check who holds a role before widening or narrowing it.

  • Give roles names and descriptions that describe the job, not the person. A role is meant to outlive the individual it was first created for.

Related Articles

  • Types of Users and Their Roles - the five system roles and what each one covers

  • Legacy Custom Roles - per-user custom permissions carried over as named roles

  • Filtering Users by Organization and Role - narrowing the Users tab by role

Did this answer your question?