Build a role
Name a set of capabilities, tick the ones it needs, and every member holding it updates together.
Open roles settings
Open Settings -> Roles.
Start a new role
Click New role. It asks first whether to start blank or from an existing role.
Name it
Give it a Name and a Description.
Tick capabilities
Tick capabilities. There is a search box and browse categories, because forty-six checkboxes need both. Categories are for finding them: there is no category-level switch, on purpose.
Mind the sensitive ones
Ones flagged Sensitive are the ones worth a second thought: deleting things, opening consoles, revealing secrets, managing tokens, managing roles.
Optionally require two-factor
Optionally turn on Require two-factor authentication for this role.
Save
Save.
Reset to default restores a built-in role. Delete role removes one you authored.
You cannot grant what you do not hold: capabilities beyond your own reach show as Out of reach rather than pretending to be available.
See also
Did this page help you?