Custom roles and permissions
When the built-in roles (Admin / Operator / Viewer) don't fit, create a custom role with exactly the permissions you want — for example "can edit dashboards and view devices, but nothing else."
Only the Owner (or a member with Manage roles) can create custom roles, and a member can only work within their own permissions: a role you create or edit can't include anything your own role lacks. The Owner is never limited. Find them on the Team page under the Roles tab.
Create a role
- Go to Team → Roles → New role.
- Give it a name (e.g. Field technician).
- Tick the permissions to grant. They're grouped by area:
- Devices — view, create, edit, delete, send commands
- Parameters — view, change (thresholds and tag settings)
- Gateways — view, create, edit, delete, provision (flash firmware from the browser), debug
- Dashboards — view, create, edit, delete
- Rules / Actions / Macros — view, create, edit, delete (and toggle/trigger)
- Data forwarding — view (destinations with their credentials hidden), manage (add, edit, test, switch on/off and delete destinations). Of the built-in roles, Admin has both, Viewer can view, Operator has neither.
- Billing — view (the plan, orders and invoices). Changing the plan, paying and managing payment methods are always Owner-only and can't be granted to a role.
- Team — view, invite, manage members; manage roles
- Save. The role now appears in the role picker when you invite or reassign a member — for anyone whose own permissions cover it.
Edit or delete a role
- Edit a role to add or remove permissions. Members holding that role pick up the change within a minute.
- You can only edit or delete a role that sits within your own permissions — a role that can do something you can't is off limits. Editing the role you hold yourself can only remove permissions, never add them; if a role needs to grow beyond what you hold, ask the Owner or another admin.
- Delete is blocked while the role is still assigned to someone — reassign those members first, then delete.
Viewing comes with every permission
Any permission in an area includes viewing that area — Edit devices includes View devices, Manage data forwarding includes View data forwarding. You don't have to tick the view box separately, and older custom roles that only ticked "edit" keep working. The reverse also holds: a role with no permission in an area can't open it at all — with nothing ticked under Rules, the Rules page isn't available to that member.
Tips
- Start from the closest built-in role in your head, then grant the extra permissions you need.
- Grant view permissions generously and edit/delete sparingly — least privilege keeps mistakes contained.
- Reserved names (Owner, Admin, Operator, Viewer) can't be reused for custom roles.
See also: Team members and roles · Inviting team members.