Compose an administrator role
Create a custom administrator role from the capability catalog in the Admin Workspace, read what each capability permits, and delete a role nobody holds.
Create a role from the catalog
In the Admin Workspace, Administrators → Roles lists the built-in roles and any custom ones, each showing how many capabilities it carries and how many people hold it. A role is composed from the platform's fixed catalog rather than typed in, which is what keeps a delegated administrator from inventing authority nobody granted.
- Application
- Admin Workspace
- Path
- AdministratorsRoles
- Opens with
admin_governance.manageCreate administrator roles, decide which capabilities each one carries, and grant them to people. This is the capability that hands out authority, so treat it as the most consequential one on the list after deleting the account.
- Context
- Account-wide, for administrators who govern the Account.
Create a role from the catalog
Read what a capability permits
Administrators → Capabilities is the reference behind the wizard: every capability the platform defines, what it lets someone do, which product it opens, and which of your roles grant it.
- Application
- Admin Workspace
- Path
- AdministratorsCapabilities
- Opens with
admin_governance.viewRead the administrator roles that exist and see who holds each one. Enough to answer who can do what, without being able to change it.
- Context
- Account-wide, for administrators who govern the Account.
Read what a capability permits
Delete a role
A custom role can be deleted only once nobody holds it. Built-in roles cannot be deleted at all.
Delete a role
If you don't see this
Each control on these pages exists only for someone who may use it. When something described above is missing, one of these is why:
Tell us how we can improve this guide.