Roles
What a role is, why there are two different kinds, and which one you are looking at.
Overview
A role is a named bundle of things someone is allowed to do, granted to a person somewhere rather than everywhere. That definition holds for both kinds of role in Canopy, which is exactly why they are easy to confuse.
The difference is who holds it. One kind is held by your application's end users; the other is held by your staff, the administrators.
Two kinds of role
Same word, two objects, and you meet both in the Workspace.
What a role contains
An end-user role contains permissions, which are the individual actions your application recognises: view a record, approve an order, export a report. Your developers define that vocabulary, one Environment at a time, and group the permissions into roles you can hand out. A role carries no place of its own: where it applies is decided when you assign it, which is what lets the same Nurse role mean one ward for one person and a whole hospital for another.
Who makes them
End-user roles and the permissions inside them are built in the Developer Console, because they describe what your application can do and only the people building it know that. What reaches you is the finished list, narrowed to the ones you have been permitted to grant.
If a role you need does not exist, that is a conversation with your developers. If it exists but is not offered to you, that is a conversation with an account administrator, who decides which roles you may hand out.
Next Step
Tell us how we can improve this guide.