API Docs / Operations / Roles

Roles

Custom (tenant-defined) roles granting per-entity capability sets. Capabilities are independent flags — granting Import does not imply Delete; Admin on an entity grants everything on it. Create and update cap the requested grants at the capabilities the requesting user holds, so a role manager can never hand out more access than they have. Deletion is blocked while users are assigned to the role. The built-in system roles (Admin, Standard User, Viewer) are code-defined and not managed here.