Creating a role and setting what it can do | Doghouse SaaS Knowledge Base     [Skip to content](#main)  [ ![Doghouse SaaS Knowledge Base](/storage/branding/01M3N8PQ7PSDNQBBKKJM6XGW03.svg) ](https://nginx.deploy-lagoon-production.districtcms-docs.dh1.amazee.io)  [Product documentation](/articles) [Roadmap](/roadmap)   Toggle navigation      

  [Product documentation](/articles) [Roadmap](/roadmap)  

  1. [Home](/) ›
2. [Product documentation](/articles) ›
3. [Users, permissions &amp; security](/articles?category=13) ›
4. Creating a role and setting what it can do

 Creating a role and setting what it can do
==========================================

Updated 5 days ago · 4 min read

 Search     Search  

Overview
--------

Every account on the site holds at least one role, and the role decides what that person can actually do once they are signed in.

The roles that ship cover the common cases: someone either writes content or administers the site. A new role is for the case in between.

Sometimes a job needs a mix that neither of them offers. A records officer who should read form submissions, say, but who has no reason to create pages or change settings.

The alternative is to hand out an administrator account, which grants far more than the job needs. A role of your own grants exactly what it does need, and nothing more.

Creating the role and deciding what it can do are two separate screens, in that order. A new role starts with no permissions at all, so it is harmless until you grant something.

> **⚠️ Important:** This is administrator work. Content editors cannot reach these screens.

---

Creating the role
-----------------

1. Go to **People**, then the **Roles** tab.
2. Press **Add role**.
3. Fill in the **Role name**. This becomes a column heading on the permissions grid and appears beside each account that holds it, so name it after the job rather than the person.
4. The **Machine name** beside the box fills itself in as you type. Leave it alone, unless you have a reason to change it, in which case use the **Edit** link next to it.
5. Press **Save**. The new role joins the bottom of the list.

![The Add role form with Records officer typed into Role name and the machine name filled in beside it, outlined in red.](/storage/ov7EgrsQj811jD5moy5e4oX1NvkeC9GIXz9SbzNs.png)

> **💡 Note:** A new role holds no permissions at all. Until you grant some, an account given this role can do nothing beyond what any signed-in account can already do.

---

Choosing what the role can do
-----------------------------

There are two ways into the same checkboxes, and which you want depends on the job.

Screen

What it shows

The **Permissions** tab under **People**

Every role side by side, one column each. Use it when you are comparing roles or granting the same thing to several.

**Edit permissions** on a role’s own row

That role alone, in a single column. Use it when you are setting one role up, which is far easier to read.

Permissions are grouped by the feature they belong to, and there are several hundred of them. A **Filter by permission name** box sits above the grid, which is quicker than scrolling when you know roughly what you are after.

Tick what the role should be allowed to do, then press **Save permissions**.

![The Permissions grid with a column for each role and the Administrator column, ticked and greyed out all the way down, outlined in red.](/storage/IhVFOYu90G254EivuMDPenqiivstFHiwpe60Pljg.png)

> **⚠️ Important:** The **Administrator** column is ticked all the way down and cannot be changed. That role is nominated under **People**, then **Role settings**, as the one automatically granted every permission, including any that arrive later with a new feature. That is exactly why it should be given sparingly.

> **💡 Note:** A permission ticked for **Authenticated user** applies to everyone who is signed in, whatever other role they hold. You can spot these on the grid: every other role shows the same permission ticked and greyed, because it is already granted. If something should be limited to one role, do not tick it on that row.

---

Giving the role to someone
--------------------------

A role does nothing on its own. It takes effect when an account holds it, and the roles an account holds are set on that account’s own form.

You can choose the role as you create the account, or add it to an account that already exists. See [**Create a user account**](/articles/create-a-user-account).

---

Renaming, changing or deleting a role
-------------------------------------

Each row on the **Roles** screen carries **Edit**, with the rest behind the arrow beside it.

![The arrow beside Edit on the Content editor row of the Roles screen, opened and outlined in red to show Edit permissions and Delete.](/storage/OTM3GcAcGmFDFuB38KqZtmykcUQoXnSZQ6XZys3b.png)

Choice

What it does

Edit

Renames the role. The machine name stays as it was, and nothing about its permissions changes.

Edit permissions

Opens that role’s own permissions page. A change takes effect immediately for everyone holding the role.

Delete

Removes the role from the site, after a screen asking you to confirm.

> **⚠️ Important:** Deleting a role strips it from every account that held it.
> 
> The accounts themselves survive and can still sign in, but they lose whatever that role allowed them to do.
> 
> Check who holds a role before you remove it.

> **💡 Note: Anonymous user** and **Authenticated user** offer no **Delete**. The site needs both, because they describe visitors and signed-in accounts rather than a job somebody does.

  Related articles 
------------------

- [ Roles and what they let you do → ](/articles/roles-and-what-they-let-you-do)
- [ Configure content workflows → ](/articles/configure-content-workflows)
- [ Create a user account → ](/articles/create-a-user-account)

 Was this article helpful?
-------------------------

Your feedback helps us prioritise what to rewrite.

      Yes     No  

 [    Back to Users, permissions &amp; security ](/articles?category=13) 

 On this page 

**Need additional help?** 
Submit a support request through the [**support portal** ](https://doghouse.atlassian.net/servicedesk/customer/portals)or email 

 © 2026 [Doghouse SaaS](https://doghouse.agency) [Glossary](/articles/glossary)
