ProdgatorDocs
Administration

Custom roles

Build a role from a base role and extra permissions, and what stays with admins.

Availability

Business plan and above. Admins create custom roles in the Admin Console under Roles.

A custom role starts from a built-in base role (reader, operator, editor or admin) and can add extra permissions from the list below. Members with the role can do everything the base role can, plus the extra permissions. A custom role never takes permissions away: to give someone less, pick a lower base role.

PermissionIncluded fromWhat it allows
Cancel runsoperatorCancel GitHub Actions runs that are still running
Re-run runsoperatorRe-run failed jobs of finished GitHub Actions runs, and re-run one finished GitHub Actions or GitLab job
Generate AI resultsoperatorAsk for AI summaries and explanations
Work with Jira issuesoperatorCreate, link and unlink Jira issues
Approve deploymentseditorApprove, reject and re-evaluate deployment gates
Roll back deploymentseditorStart a rollback to an earlier deployment
Triage security findingseditorDismiss, reopen, split and rejoin alerts, scan results and findings
Upload security reportseditorUpload scanner reports
Run compliance evaluationseditorStart a compliance evaluation
View enforcementeditorSee enforcement decisions, settings and break-glass overrides
View SPACE metricseditorOpen the SPACE developer metrics
Export dataeditorStart data exports and download them
Share AI widgetseditorShare AI widgets with the organization and edit shared ones
See the member listeditorSee member names and emails, for example to pick approvers
Manage custom adapterseditorCreate and edit custom adapters and processing rules
Edit release policiesadminCreate, edit, import and bind release policies
Edit approver groupsadminCreate and edit approver groups
Edit gatesadminCreate and edit gates and the deployment environments they link
Manage compliance policiesadminTurn policies on or off, set enforcement modes and settings, re-evaluate decisions

For example, a "Release manager" role based on operator with Approve deployments and Roll back deployments lets someone control runs and answer deployment gates without the rest of the editor role.

Some actions stay with admins and cannot be added to a custom role: managing members, roles and invitations, API keys, billing, integrations, organization settings, break-glass overrides, overriding a deployment decision made by a Block compliance policy, and overriding a release policy. Only a custom role with the admin base role includes them, and that gives full control of the organization.

Good to know:

  • Changes to a role apply to its members within about five minutes.
  • If your organization moves to a plan without custom roles, members keep the custom role's base role and lose the extra permissions until you upgrade again.
  • Deleting a custom role removes it from its members. They keep their other roles, or become readers.
  • The Users page shows what each member can actually do: the role they act as and any extra permissions.
  • Creating, changing and deleting roles is recorded in the audit log.
  • The admin console will not let a role change or deletion leave the organization without an admin.