Custom user roles
Custom User Roles let define tenant-specific roles with a selected set of rights. Can be used when the predefined system roles do not match your organization's responsibilities.
Custom roles appear next to the standard roles when assigning roles to users. A user can have multiple roles, including a mix of standard and custom roles. For an overview of the predefined roles and available rights, see Rights and Roles.
Note: Only users with Access Management write permission can create, edit, or delete custom roles. Users with Access Management read permission can view the roles overview and role details.
Where to find the settings
Navigate to:
Administration → Users → Roles
The overview lists all roles available in the tenant, both standard roles and custom roles. For each role, the table shows the name, ident, type, deprecated status, and rights.
Select a role to open its detail page. Custom roles can be edited or deleted from the overview and from the detail page.
Create a custom role
- Open Administration → Users → Roles.
- Select Add.
- Enter a display name for the role.
- Select the rights that the role should grant.
- Save the role.
After saving, the system creates a unique role ident (for example CUSTOM_ROLE_…). The role is immediately available for assignment to users.
Fields
| Field | Description |
|---|---|
| Display name | Human-readable name shown in the roles overview and when assigning roles to users. |
| Rights | The permissions granted by this role. Select only the rights required for the intended responsibilities. |
Example
You want a role for users who should view customers and documents, but must not change configuration or manage users.
Create a custom role with:
- Display name:
Customer Support Read - Rights: Customer Management read, Document Management read, Contract and Order Management read
Assign this role to the relevant users. They can review the selected areas without receiving broader write permissions.
Edit a custom role
Open the edit action on a custom role in the overview, or open the role detail page and edit from there.
You can change:
- the display name
- the selected rights
Save to apply the changes. Users who already have this role receive the updated rights.
Standard roles cannot be edited.
Changes to custom roles are recorded in the Audit Trail.
Delete a custom role
Use the delete action on a custom role in the overview or on the role detail page, then confirm.
When you delete a custom role:
- the role is removed from the tenant
- a corresponding entry is written to the Audit Trail
Standard roles cannot be deleted.
Note: A custom role can only be deleted when it is no longer assigned to any user. If the role is still assigned, a list of the affected users is shown so you can remove the assignment before deleting the role.
Assign custom roles to users
Custom roles are assigned in the same way as standard roles.
- Open Administration → Users
- Create a new user or edit an existing user
- In the User roles section, select the custom role (and any other roles as needed)
- Save
A user can have multiple roles at the same time. The effective permissions are the combined rights of all assigned roles.
For more information on user management, see Manage Users.
Custom roles and SSO
If Single Sign-On is configured, custom roles can be used as target roles in Role Mappings. Users then receive the matching custom role automatically based on claims from the identity provider.
For more information, see Role Mapping for SSO Configuration.
Best practices
Follow least privilege
Assign only the rights required for a role's responsibilities. Prefer several focused custom roles over one role with broad write access.
Prefer reusable roles
Create roles around teams or responsibilities (for example Finance Read, Support Read/Write) instead of one-off roles per person.
Review after changes
After editing or deleting a custom role, review affected users to confirm that their remaining roles still match their intended access.
Updated about 12 hours ago