Create or Edit a Custom Role

Build a least-privilege role from the permission matrix and validate it before broad assignment.

Written By 4ALL.LIVE

Last updated 12 days ago

Build a least-privilege role from the permission matrix and validate it before broad assignment.

Best for: Owners and authorized administrators.

Before you start

Custom-role availability may depend on plan; only authorized users can create/edit/delete roles.

  • Sign in with an individual account in the correct organization.
  • Confirm your role permits the requested change.
  • Record the current state and intended owner before making a production-impacting change.

Steps

  1. Write the job definition. List exact resources and actions the role must perform.
  2. Open Roles & permissions. Confirm organization and inspect existing roles to avoid duplicates.
  3. Create the role. Use a clear responsibility-based name and description.
  4. Select permissions. Grant only required actions for events, live operations, Remote Control, takeover, ASL, exports, organization, teams, billing, or integrations.
  5. Save and test. Assign to a non-production test member in a test team/event.
  6. Run allow tests. Confirm every required action succeeds.
  7. Run deny tests. Confirm billing, deletion, ownership, credentials, and unrelated events remain blocked.
  8. Deploy and review. Assign gradually, document owner, and schedule review.

What success looks like: The requested change is applied to the intended organization, is visible after refresh, and grants no more access than required.

Check your setup

  • The role passes both allowed and denied action tests and is assigned only to people performing that job.

Troubleshooting

User cannot perform required action

Identify the specific resource/action and add only that permission.

Role appears broader than matrix

Check owner/admin status, team permissions, other roles, and cached session.

Cannot delete role

Remove assignments and confirm only an owner performs the deletion if required.

Security and operational notes

  • A custom role is security configuration and should be reviewed like code.
  • Never test destructive permission on live customer data.
  • Record changes and approvers.