Roles and access
A role is a set of permissions in one app. Anything a role does not allow is refused, and a deny always wins over an allow.
Make a role in Pages
Start a role
In the sidebar, under People, choose Roles, then New role. Give it a Name and a Description.
Scope
Under Applies to, choose The whole organisation, or limit the role to Locations, Programmes or Events. Then choose which: all of them, chosen ones, or Each holder’s own — picked for each person when they are given the role.
Permissions
On Site and content, Events and money, People and users and Organisation, tick Read or Edit for each area, plus extras such as Publish, Refund payments and Review applications.
Members
On Members, choose Assign role for an existing user, or Invite with this role for someone new.
Save
Check the Review step and choose Confirm and create.
Built-in roles
Built-in roles keep their scope. To change one, choose Duplicate in the Roles list and edit the copy.
In Reach and Shop, you choose from the app’s roles when you invite someone; if an organisation has none yet, Install default roles adds the standard set. In Shop, roles apply to the whole shop.
In HR, permissions are set under Admin → Permissions, as policies attached to roles.
Confirm it’s you
Widening someone’s access — making them an administrator, for example — asks for a fresh sign-in from the last few minutes. Use your passkey, or have a new sign-in link emailed to you; you return to the change you were making.