How to edit a role

Change what an existing role grants. Menus, data sources, dataset and field restrictions, Report access, or organizational scope. Edits apply to everyone who holds the role, so the reach of a change is wider than it looks.

Before you begin

You need:

  1. The Account Admin role
  2. The name of the role you’re editing
  3. A sense of who currently holds it. An edit here reaches all of them at once

Security tags aren’t changed on this form. They’re attached from the Security action in the role’s row. See How to assign a security tag to a role.

Widening a role is safe; narrowing one needs checking first. Adding access affects only what people can newly reach. Removing access can break work already in progress, and it often doesn’t take effect at all. If any other role or group grants the same thing, the user keeps it. Before you narrow a role, know who holds it and what else they hold.

Steps

Step 1. Open Roles Management

From the main navigation, click Admin, then open the Roles Management tab.

Step 2. Find the role

Type the role name into the search bar at the top of the list. Matching roles appear as you type. Use the pagination controls at the bottom to browse if you’d rather scan the full list.

Step 3. Open it for editing

Click the edit icon in the role’s Settings column. The role opens on the Menu Access tab with its current configuration loaded.

Step 4. Change what you need

Move between the Menu Access and Advanced tabs as needed. The fields are the same ones you set at creation. See How to create a role for what each controls.

Two that are worth re-checking whenever you’re in here:

  1. Reports Access — this doesn’t update itself. Reports built since the role was last edited aren’t included, and this is the most common reason a new Report is invisible to a team that should see it.
  2. Restrict Field Access and Restrict Dataset Access — these match on exact names. If anything was renamed at the data source, the restriction has stopped applying silently.

Step 5. Save

Click Save. The change applies to everyone currently assigned the role, no reassignment needed.

Result

The role’s new configuration is live and everyone holding it is affected. Nothing about the assignments themselves changes: the same users and groups hold the role, with the access it now describes.

If you widened the role, the new access appears for its holders. If you narrowed it, access is removed only where no other role or group still grants the same thing.

Common issues

  1. I removed a permission and users still have it. They hold it through another role, a group, or a parent group. Access is the union of every source, so removing it in one place changes nothing on its own. See How to work out why a user can’t see something.
  2. A new Report isn’t visible to the team. It wasn’t added to Reports Access. New Reports aren’t picked up automatically, open the role and check the box.
  3. The menu I want isn’t offered. It belongs to a product the workspace doesn’t subscribe to.
  4. Field restrictions stopped working. A column was renamed at the data source. Restrictions match by exact name, including case, and fail silently when the name changes.
  5. My change affected more people than expected. Roles are shared. Check who holds it before editing, and create a separate role when only some of them need the change.