Skip to content

Roles

A role is a bundle of permissions that controls what a user can view, create, and manage across the platform.

Roles are how Octo turns permissions into reusable access profiles. Instead of granting access one permission at a time to each user, you define a role once and assign it wherever it belongs.

  • A role is the reusable access profile.
  • A permission is a single allowed action.
  • A user receives one or more roles and therefore all permissions inside them.

Permissions themselves are system-defined. The administration work here is choosing how to bundle them sensibly.

  1. Select Settings > Roles in the sidebar.
  2. Click Create Role.
  3. Enter a role name and optional description.
  4. Click Save Role.
  1. Open the role from the list.
  2. In the Permissions tab, click Assign / Unassign Permissions.
  3. Move permissions between the Available and Assigned lists. Both lists are searchable.
  4. Click Save.

Assigned permissions appear in the permissions grid with the assignment date.

Use a role review before assigning access to production users.

  • Scope Confirm whether the role is for system settings, product operations, or both.
  • Write permissions Separate create, update, delete, and export permissions where possible.
  • Sensitive settings Restrict API keys, audit logs, environment settings, and billing-related access carefully.
  • Runtime access Limit workflows, tools, phone numbers, and interactions to teams that actually operate them.
  • Review cadence Revisit roles whenever teams or responsibilities change.

Permissions are system-defined. If a permission does not exist in the picker, record the access need as product feedback instead of creating a naming workaround.

Role detail page showing the permissions grid for an assigned role

Single delete:

  1. Open the role you want to remove.
  2. Click Delete Role.
  3. Confirm the deletion.

Bulk delete:

  1. Select Settings > Roles in the sidebar.
  2. Select the checkboxes next to the roles you want to remove.
  3. Click Delete Selected.
  4. Confirm the deletion.

What are the default roles? Three default roles exist: Administrator (full access), Editor (create and modify), and Viewer (read-only). You can customize these or create new roles.

Can I edit permissions themselves? No. Permissions are system-defined. You can only assign or unassign them from roles.

  • Users — assign roles to users
  • Audit Logs — review role and permission changes