Skip to main content

Roles

Who can do this

authz-role:read. Administration → Users & Roles → Roles.

Roles

This page is a reference, not a workshop. It tells you what each role can do so you can pick the right one on the Add user form.

The counts across the top are for the whole realm: 18 roles, of which 3 are custom, drawing on a catalogue of 107 permissions.

Each row gives the role's display name, its system identifier (tpa-gatekeeper), a one-line description where the role has one, how many permissions it grants, how many people hold it, and its status. Roles marked System are built in and cannot be edited or deleted.

The ⋮ menu on a system role offers only View, which opens the full list of permissions that role grants. A custom role can also be edited here.

Role row menu Viewing a role's permissions

Editing a custom role

The editor will not save until the permission matrix has finished loading — "Permissions are still loading" — so a role can never be saved with an empty permission set by accident. If the catalogue cannot be loaded at all, it says so instead of offering to save.

A role change is applied one permission at a time. If part of it does not go through, the dialog reports the partial result rather than claiming success, so you know to reopen the role and check it.

For what each role means in practice — where it lands, what it can open, what it is refused — see Role reference.