Create or Edit a Custom Role
Build a least-privilege role from the permission matrix and validate it before broad assignment.
Written By 4ALL.LIVE
Last updated 12 days ago
Build a least-privilege role from the permission matrix and validate it before broad assignment.
Best for: Owners and authorized administrators.
Before you start
Custom-role availability may depend on plan; only authorized users can create/edit/delete roles.
- Sign in with an individual account in the correct organization.
- Confirm your role permits the requested change.
- Record the current state and intended owner before making a production-impacting change.
Steps
- Write the job definition. List exact resources and actions the role must perform.
- Open Roles & permissions. Confirm organization and inspect existing roles to avoid duplicates.
- Create the role. Use a clear responsibility-based name and description.
- Select permissions. Grant only required actions for events, live operations, Remote Control, takeover, ASL, exports, organization, teams, billing, or integrations.
- Save and test. Assign to a non-production test member in a test team/event.
- Run allow tests. Confirm every required action succeeds.
- Run deny tests. Confirm billing, deletion, ownership, credentials, and unrelated events remain blocked.
- Deploy and review. Assign gradually, document owner, and schedule review.
What success looks like: The requested change is applied to the intended organization, is visible after refresh, and grants no more access than required.
Check your setup
- The role passes both allowed and denied action tests and is assigned only to people performing that job.
Troubleshooting
User cannot perform required action
Identify the specific resource/action and add only that permission.
Role appears broader than matrix
Check owner/admin status, team permissions, other roles, and cached session.
Cannot delete role
Remove assignments and confirm only an owner performs the deletion if required.
Security and operational notes
- A custom role is security configuration and should be reviewed like code.
- Never test destructive permission on live customer data.
- Record changes and approvers.