Managing roles
A role is the only thing in Elie that carries permissions — departments and groups carry none. Everything a person may do comes from their role.
- The Access Control module visible in your left-hand navigation.
- These permissions: Roles & Permissions · Role — CREATE, Roles & Permissions · Role — UPDATE.
- Nothing else — Access Control is visible to everyone, so a missing permission only shows itself when you save.
If Access Control isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.
Steps
Select Access Control in the left-hand navigation, then Roles. Each row shows its TYPE — CUSTOM or SYSTEM — its KEY, and its PERMISSIONS count.
Select Add Role, in the header of every Access Control page. Enter a Role Name; the Role Key follows the name until you edit it, and cannot be changed later. Select Create.
The new role opens with none. Under Permissions, each row is one feature and the columns are VIEW, LIST, CREATE, DELETE, READ, UPDATE and EXECUTE; a
-means that feature has nothing for that column. Narrow a long list with Search by feature name.Select Save Permissions, available once your ticks differ from what is stored. Reset Changes puts them back.
Edit Basic Details changes the Role Name and Description; select Update.
What success looks like
- Role created successfully! appears and the role’s own page opens.
- Permissions saved successfully! appears, and the PERMISSIONS count on Roles matches your ticks.
System roles resist editing
Roles badged SYSTEM arrive with your workspace: no delete icon, and no change is accepted to their Role Name or Description. Their permissions still save — except on Tenant Administrator, which holds every permission and reads This is a locked system role and cannot be modified. with every checkbox inactive. To vary a system role, select Add Role and build your own.
If something goes wrong
| Symptom | Likely cause | What to do |
|---|---|---|
| No delete icon on a role’s row. | It is a SYSTEM role — hidden, not greyed out. | Only a CUSTOM role can be deleted, so build one. |
| A red message says the role key already exists. | Another role uses that Role Key. | Keys are permanent — create the role again under a different key. |
| The role exists but nobody has it. | A role reaches a person only at invitation. | Pre-assign it under Pre-Assign — see Inviting a user. |
| The module is replaced by Access Forbidden. | Your own role lacks the permission for that action. | Select Go Back, then ask an administrator. |
Next
- Inviting a user — the one place a role is assigned.
- Permissions reference — what each permission family covers.