Custom Roles and Permissions in Settings
Settings adds fully custom roles alongside the default admin/member roles, letting a workspace define exactly what a role can see and do, app by app.
Workspace and team management has covered the basics well since it was refined — admin and member roles, per-app access — but every workspace eventually has a role that doesn't fit either default cleanly: a contractor who should see one app but not others, a finance-only role that shouldn't touch CRM, a read-only reviewer. Today's release adds fully custom roles.
How it works
From Settings → Team → Roles, a workspace admin can create a new role from scratch or by cloning an existing one, then configure exactly what it can do, app by app — view, edit, or no access at all — and, for apps with more granular permissions already, like CRM's pipeline visibility or Finance's approval permissions, custom roles can be scoped down to those specifics too. A custom role can be assigned to any workspace member the same way the default roles are, and a person can be moved between roles at any time without losing their historical activity or content ownership. The new audit log shipped earlier tracks every role change and assignment, so who has access to what — and who granted it — is never a mystery.
Where this is useful
This is aimed at workspaces whose real access needs don't map cleanly onto "admin" and "member" — agencies giving clients limited read-only access to specific projects, businesses with contractors who need one app and nothing else, or larger teams that want a finance-specific or support-specific role with exactly the right boundaries rather than granting broader access than a person actually needs.
What's included
Custom role creation, app-level and select feature-level permission scoping, and role cloning are live today. Time-limited role assignments — automatically reverting a temporary elevated role after a set period — are planned for a follow-up release.
Custom roles are available now on plans that include advanced security features, alongside the default admin and member roles, which remain unchanged for workspaces that don't need anything more granular.