Roles
Learn how to create, edit and delete a role.
Last updated
Learn how to create, edit and delete a role.
Last updated
A role is a set of permissions that can be granted to groups. These permissions can change depending on which environment the user is in: test or production.
The Roles page shows you a table with active roles in your realm.
This table shows the role name and description, as well as buttons to view, edit, and delete them.
To create a role:
Click on the Create button, in the upper right corner.
Fill in the name and description of the role.
Click on the dots under the columns Create, Read, Update, Delete, and Specific to activate or deactivate a permission for the service described in each row. Activated permissions are represented by green checkboxes.
Click on Save.
To view a role:
Search the table for the role you want to edit, or use the search bar.
Click on the pencil or eye icon in the Actions column.
To edit a role:
Make the desired changes to the role.
Click on Save.
System roles cannot be edited, and can be viewed under the eye icon.
To duplicate a role:
Search the table for the role you want to duplicate or use the search bar.
Click on the pencil or eye icon in the Actions column.
Click on Duplicate role.
Make the desired changes to the new role.
Click on Save.
When you delete a role, the permissions granted by that role become inactive.
To delete a role:
Search the table for the role you want to delete or use the search bar.
Click on the box icon in the Actions column.
Write a note describing the reason for archiving that role.
Click on Confirm.
System roles cannot be deleted, just the ones created by users.
With the account-environment-manager, api-key-manager, deployment-manager, global-environment-manager and pipeline-manager roles, you can define the environment (test or production) as a parameter, ensuring that a group of users has specific permissions to perform certain tasks only in the selected environment. If the environment is not defined, the user has access to all environments.
Users with account-viewer, api-key-viewer, deployment-viewer, global-viewer, and pipeline-builder can only perform certain actions in environments (test or production) that have been previously defined by the user responsible for managing access to the environments.
Besides creating your own roles, you can also use Digibee’s predefined system roles. You can’t edit or delete system roles, but you can duplicate them and edit their replicas.
Below, you can see all current existing system roles and their respective permissions: