How to assign a role to an existing user
Give someone already in your workspace additional access by adding a role to their profile. Roles are additive, so assigning a new role expands what a user can do without disturbing the access they already have.
Before you begin
You need:
- The Account Admin role. Only Account Admins can change role assignments
- The user’s user identifier or email address, so you can find them in the list
- The role you plan to assign. If it’s a custom role, create it in Roles Management first
- If you’re removing a role: a list of the groups the user belongs to, since roles granted through a group can’t be removed from here
Roles are additive. A user’s effective access is the union of every role they hold, whether assigned directly on their profile or inherited through group membership. Adding a role never takes access away. Removing one only removes access that no other role grants.
This article covers direct role assignment on a single user. To change access for a whole team at once, assign the role to a group instead, see How to create a group.
Steps
Step 1. Open User Management
From the main navigation, click Admin, then open the User Management tab.
Step 2. Find the user
Type the user’s user identifier or email address into the search bar. The list narrows as you type. If you don’t know either, use the pagination controls to browse the full list.
Step 3. Open the role assignment option
In the user’s row, open the settings menu and select Assign Role. The role selection panel opens with the user’s current roles assigned.
Step 4. Select the roles
Check the roles this user should hold. Remove any role you do not want the user to hold.
Common combinations:
- Account Admin + Lens Designer — for admins who also build dashboards
- Lens Designer + Viewer — for Designers who also consume reports built by others
- Viewer only — for users who only need to see shared dashboards
Removing a role is not the same as revoking access. If the user holds the same permission through a second role or through a group, they keep it. When you need to be certain access is gone, check every role the user holds and every group they belong to.
Step 5. Save
Click Save to apply the change.
Result
The user’s profile now reflects the roles you selected, and their access is the combined total of those roles plus anything they inherit from groups. Menus, data sources, and Reports granted by the new role become available to them.
You can revisit this at any time from User Management. Role assignment is non-destructive, nothing the user has created is affected by adding or removing a role.
Common issues
- The role I need isn’t in the list. Roles for products you don’t subscribe to won’t appear. Weave Designer won’t show on a workspace without Weave. Custom roles also don’t appear until someone creates them in Roles Management. Create the role first, then come back.
- I removed a role but the user still has the access. The user holds the same access through another role or through a group. Roles are additive across every source. Check the user’s remaining roles first, then their group memberships.
- I added a role and the user says nothing changed. Ask them to sign out and back in. If access still hasn’t appeared, confirm the role itself actually grants what you expect, open it in Roles Management and check its Menu Access and Advanced settings.