Manage custom roles

Updated at:
Copy as MD

You can quickly authorize accounts using default roles. For more granular control, create custom roles with specific permissions.

Create a custom role and grant it to a target account

When creating a custom role, you can select a role (member or administrator) and its associated permissions. You then grant this role to a target account, which gives the account the necessary permissions to perform operations in Account Center and Expenses and Costs.

Prerequisite: To grant the role to an account immediately, ensure the account already exists.

  1. Log on to the Account Center as an enterprise administrator. Under My Entity, choose Roles and Permissions.

  2. On the Role Settings tab, click Create Custom Role to configure the role's basic information and permissions.

    The basic information includes Role Name and Role Description. In the Associated Permissions area, click Add Permission to associate specific permissions with the role.

    Choose the Permission Scope for the custom role carefully. You cannot modify this setting after creation. To change it, you must delete and re-create the role. The Permission Scope types are as follows:

    • Administrator role: Accounts with this role have management permissions over other accounts.

    • Member role: Accounts with this role have only the permissions assigned to it.

  3. Click Confirm Creation. This action creates the custom role.

    In the success prompt, click Go To Authorization Page To Grant Permissions to enter the authorization page, or click Back to List to go back to the role list.

  4. Click Go To Authorization Page To Grant Permissions, then click Add Granted Account.

    In the Add Granted Account dialog box, filter target accounts by using the Department drop-down list or search box, select the accounts, and then click Confirm Add.

  5. Click Confirm Add to view accounts with this role.

    Note

    Click Remove Grant to revoke the role from an account.

Modify a custom role

You can modify the name, description, and associated permissions of any role on the Role Settings tab, except for default roles. You can then grant the modified role to a target account.

  1. Log on to the Account Center as an enterprise administrator. Under My Entity, choose Roles and Permissions.

  2. On the Role Settings tab, in the Actions column for the target role, click Details.

  3. On the Role Information tab of the target role, click Modify Role to change the role's name and information, add permissions, or remove permissions.

  4. Click Confirm Changes.

    • Click the Go To Authorization Page To Grant Permissions button to grant the custom role to a destination account. For more information, see Step 4 to Step 5.

    • Click Back to List to return to the Role Settings tab and view all roles.

Delete a custom role

Before you delete a role, check which accounts are granted it to avoid unintended permission changes. After you delete a role, any account that was granted it will lose the associated permissions.

  1. Log on to the Account Center as an enterprise administrator. Under My Entity, choose Roles and Permissions.

  2. On the Role Settings page, in the Actions column for the target role, click Delete.

  3. Click Confirm Delete. After the role is deleted, the authorized accounts will lose the corresponding permissions.