Custom roles and permissions
When the built-in roles (Admin / Operator / Viewer) don't fit, create a custom role with exactly the permissions you want — for example "can edit dashboards and view devices, but nothing else."
Only the Owner (or a member with Manage roles) can create custom roles. Find them on the Team page under the Roles tab.
Create a role
- Go to Team → Roles → New role.
- Give it a name (e.g. Field technician).
- Tick the permissions to grant. They're grouped by area:
- Devices — view, create, edit, delete, send commands
- Parameters — view, change (thresholds and tag settings)
- Gateways — view, create, edit, delete, provision, debug
- Dashboards — view, create, edit, delete
- Rules / Actions / Macros — view, create, edit, delete (and toggle/trigger)
- Team — view, invite, manage members; manage roles
- Save. The role now appears in the role picker when you invite or reassign a member.
Edit or delete a role
- Edit a role to add or remove permissions. Members holding that role pick up the change within a minute.
- Delete is blocked while the role is still assigned to someone — reassign those members first, then delete.
Tips
- Start from the closest built-in role in your head, then grant the extra permissions you need.
- Grant view permissions generously and edit/delete sparingly — least privilege keeps mistakes contained.
- Reserved names (Owner, Admin, Operator, Viewer) can't be reused for custom roles.
See also: Team members and roles · Inviting team members.