Go to Settings → Roles & Permissions. You will see the built-in roles and any you have created.
Start from something that nearly fits
Duplicate the closest built-in role and adjust it, instead of starting from an empty list. Building from nothing is how you end up with a role that cannot open the dashboard.
Assembling it
Permissions are grouped by area: Projects, Tasks, Time Logs, Members, Reports, Invoices, Settings and so on. Within each, switch on the actions the role should have and, where a scope is offered, choose Own, Team or All.
Some permissions depend on others. You cannot grant editing without viewing, and a sub-permission cannot have a wider scope than the permission above it. The form holds you to that instead of saving something that cannot work.
Handle these with care
- Project Finance and Member Finance reports. These carry pay rates, costs and margins. Granting them to a general reporting role exposes what every member earns.
- Payable invoices. Same information, different page.
- Mark invoices paid. That is money leaving, and it locks rates for the period it settles.
- Roles and permissions. Anyone who can edit roles can grant themselves anything.
- Billing. Changing the plan changes what you pay.
Notifications
Which notifications a role receives is set separately, in Settings → Notification Settings. A new role starts with a sensible default. Check it, or the people in that role will not hear about invitations, invoices or plan limits.
Assigning and changing it
Assign the role when inviting someone, or edit an existing member. Editing a role changes access for everyone who holds it, straight away, so make changes carefully instead of experimenting on a live role.
Deleting a role
Move everybody off it first. A role nobody holds can be deleted safely. The built-in four cannot be deleted at all.
A test that catches most mistakes
Assign the new role to one person, ask them to walk through their normal day, and fix what is missing. That takes ten minutes and beats reasoning about a list of two hundred permissions.