Intellistack Streamline includes four built-in roles (Admin, Manager, Builder, and Operator), each with a fixed set of permissions that cannot be changed. Custom Roles lets an Admin define named roles built from the platform's existing permissions, so access maps to the real responsibilities in your organization instead of forcing a choice between too much and too little access. Each role is reusable across users, viewable as a plain-language permission breakdown, and enforced consistently across the product.
Who Has Access?
| Role | Access |
| Admin | Full lifecycle: create, view, edit, delete custom roles; assign roles to users; and view a role's or a user's permission detail. Admins can grant any permission. |
| Delegated actor (a non-Admin granted role-management permissions) | Can create, edit, delete, and assign roles, but only within their own permissions. They cannot create or grant a role that includes permissions they do not hold. |
| Manager | Can assign existing custom roles to users. Assignment happens in the Users area. |
| End user (assigned a custom role) | Receives only the permissions their role grants. Restricted actions are denied consistently. Each user has one role. |
Note: Role-management permissions are themselves part of the permission catalog, so an Admin can delegate role creation and assignment to a non-Admin custom role.
Important: A delegated actor can only create, edit, and assign roles whose permissions are within their own access level. You cannot create, edit, or assign a role that includes a permission you do not hold yourself. Attempting to do so is blocked with the message: "This role includes permissions that exceed your own access level. You can't create, edit, or assign roles with permissions you don't have." Built-in Admins have no such limit. This prevents privilege escalation through delegated role management.
Key Capabilities
Create and manage roles:
- Create a named role with an optional description, selecting permissions from the platform catalog.
- Enter the name and description first, then select permissions.
- Clone an existing system or custom role and adjust its permissions instead of starting from scratch.
- Reuse a role across any number of users.
Permission selection:
- Permissions are shown as hierarchical checkboxes with inline descriptions, grouped by domain.
- Each domain is a collapsible section with a count indicator (for example, "4 of 10 checked"), plus a global selected-versus-total count for the whole catalog.
- Permission dependencies are enforced: enabling a nested permission automatically enables its parent, so a role cannot grant a dependent capability without its prerequisite.
Assign and audit access:
- Assign a role to a single user or change the role for multiple users at once.
- View a complete, plain-language breakdown of what a user role can and cannot do, grouped by domain.
- From a role, use View Users to filter the Users tab to everyone holding that role.
Enforcement:
- Pages and areas a user's role does not grant access to are hidden from navigation. Within a page a user can access, individual restricted controls are shown disabled with a clear explanation of the missing permission, rather than hidden.
- Project access requires both the relevant project permission and project membership. Neither alone is sufficient.
Create a Custom Role
- Go to the Roles page.
- The four system roles appear in the role list.
- Click New Custom Role.
- Enter a role name. Names must be unique within your organization.
- Optionally add a description. https://cleanshot.com/share/g7m1WTfM
6. Optionally add a description. https://cleanshot.com/share/g7m1WTfM
- Expand each domain section to see the permissions it contains.
- Check the permissions the role should grant. Selecting a nested permission automatically selects its required parent permission.
Use the per-domain count and the global selected count to gauge how much access the role carries.
7. Review the selected permissions before finalizing.
8. Save the role.
Note: A role must include at least one permission before it can be saved.
Clone an Existing Role
To start from a system or custom role instead of a blank role:
- Open the role you want to use as a starting point.
- For a system role (Admin, Manager, Builder, Operator), permissions are read-only. Select Duplicate Role to create an editable copy.
- Adjust the name, description, and permissions on the new role.
- Save the role.
Assign a Role to Users
Role assignment happens in the Users area.
Assign an Existing User
- Go to the Users page
- Locate the user and open the role control
- Select the custom role to apply. This replaces the user's current role.
Confirm the change.
Note: Each user can have exactly one role. Assigning a new role removes the previous one.
Change Roles in Bulk
1. On the Role Detail page, select the users you want to update. Each selected user's current role is shown.
2. Select Actions > Change role. Select the role to apply to all selected users.
3. Confirm the change
Note: A single bulk assignment is limited to 100 users per request.
View a User's Role
From the User’s Profile:
- Open the user's profile.
- The profile shows the user's assigned role
From the Role Details Page:
- Select Actions > Who has this role
- You will be navigated to the Users page where the user list will be filtered by the selected role.
From the Users page:
- Click the “All users” dropdown menu next to the search bar
- Select a role from the list
- The user list will display only the individuals assigned to the chosen role by filtering the list automatically.
Editing a Custom Role
The permission set of a custom role can be edited. To do this:
- Navigate to the Roles page
- Click on the role you wish to edit
- From the Role details page, click ‘Edit Permissions’ to edit the role’s permissions.
- Make the changes to the role’s permissions
- Save the changes.
Note: All users already assigned to the role will have their permissions updated to the new permission set when the changes are saved.
Available Permissions
Permissions are grouped by domain. The permissions available for custom roles include:
| Domain | Capabilities |
| Organization | Edit organization profile and settings |
| Users and groups | Manage users, Manage groups |
| Projects and workflows | View projects, View all project stats, Create projects, Edit project, Delete project, Manage project members, Create workflows, Edit workflows, Configure integration steps, Operate workflows, View sessions, View session identifier, Configure session identifier, View org step access controls, Manage org step access controls, View project step access controls, Manage project step access controls, Enforce step restrictions |
| Data and integrations | View datasets, Manage datasets, Activate datasets, View data catalogs, Manage data catalogs, View data integrations, Manage data integrations, Manage event integrations |
| Brands | Create brands, Edit brands, Delete brands, Manage default brand, Assign brand access |
| Role management | Manage roles, Delete roles, Assign roles |
| Custom domains | Manage custom domains |
| Security | Manage personal access tokens, Allow users to create access keys |
Feature Considerations
Role model:
- Each user has one role. Multiple roles per user and per-project roles are not supported. A user cannot hold one role in one project and a different role in another.
- Role names must be unique within an organization.
- A role must include at least one permission.
Deletion:
- A role that has users assigned cannot be deleted. Move those users to another role first.
Visibility:
- Only the built-in Admin role sees every project in the organization. For any other role, including custom roles, viewing a project requires project membership. The View Projects permission lists the projects the user is a member of, not every project in the organization. The same applies to datasets and other membership-scoped resources.
- Cloning a role copies permissions only, not resource access. Cloning the Admin role does not grant a user organization-wide access to all projects. Organization-wide project visibility is inherent to the built-in Admin role and cannot be granted through a custom role. A cloned-Admin user still needs project membership to view a given project.
Scope:
- Group-scoped or per-department roles are not available. Roles scope the actions a user can take; groups scope which resources a user can see. To approximate a department-scoped role, create per-department named roles (for example, supervisor-DEPT).
- Bulk role creation and CSV-driven assignment are not supported.
Homepage:
- Homepage widgets tied to a permission the user's role does not grant are shown in an empty state rather than populated with data.
Troubleshooting
| Issue | Cause | Resolution |
| "This role includes permissions that exceed your own access level. You can't create, edit, or assign roles with permissions you don't have." | A delegated (non-Admin) actor tried to create, edit, or assign a role that includes permissions beyond what they hold | Have an Admin perform the action, or remove the out-of-scope permissions. |
| Editing a role fails because the role changed | Someone else modified the role since it was loaded | Reload the role and re-apply your changes. |
| A user still cannot access a project despite having the right permission | Project access requires both the permission and project membership | Add the user to the project and confirm the role includes the project permission. |
| A permission change is not reflected immediately | Permission changes propagate shortly after a role or assignment edit | Allow a brief moment after editing for the change to take effect. |
| A role cannot be renamed or deleted | The role has users assigned | Move the assigned users to another role first, then rename or delete. |
| A bulk assignment returns mixed results | Each user is processed independently, so some can succeed while others fail | Review which users failed and retry those. |
Summary
Custom Roles is available to Admins in the Roles & Permissions area of Intellistack Streamline. Create a role from scratch or by cloning an existing role, assign it to users from the Users area, and review any user's access from their profile or the role detail page. Each user holds a single role, and permissions are enforced consistently across the platform.
Comments
0 comments
Please sign in to leave a comment.