Custom roles
Build a role from a base role and extra permissions, and what stays with admins.
Availability
A custom role starts from a built-in base role (reader, operator, editor or admin) and can add extra permissions from the list below. Members with the role can do everything the base role can, plus the extra permissions. A custom role never takes permissions away: to give someone less, pick a lower base role.
| Permission | Included from | What it allows |
|---|---|---|
| Cancel runs | operator | Cancel GitHub Actions runs that are still running |
| Re-run runs | operator | Re-run failed jobs of finished GitHub Actions runs, and re-run one finished GitHub Actions or GitLab job |
| Generate AI results | operator | Ask for AI summaries and explanations |
| Work with Jira issues | operator | Create, link and unlink Jira issues |
| Approve deployments | editor | Approve, reject and re-evaluate deployment gates |
| Roll back deployments | editor | Start a rollback to an earlier deployment |
| Triage security findings | editor | Dismiss, reopen, split and rejoin alerts, scan results and findings |
| Upload security reports | editor | Upload scanner reports |
| Run compliance evaluations | editor | Start a compliance evaluation |
| View enforcement | editor | See enforcement decisions, settings and break-glass overrides |
| View SPACE metrics | editor | Open the SPACE developer metrics |
| Export data | editor | Start data exports and download them |
| Share AI widgets | editor | Share AI widgets with the organization and edit shared ones |
| See the member list | editor | See member names and emails, for example to pick approvers |
| Manage custom adapters | editor | Create and edit custom adapters and processing rules |
| Edit release policies | admin | Create, edit, import and bind release policies |
| Edit approver groups | admin | Create and edit approver groups |
| Edit gates | admin | Create and edit gates and the deployment environments they link |
| Manage compliance policies | admin | Turn policies on or off, set enforcement modes and settings, re-evaluate decisions |
For example, a "Release manager" role based on operator with Approve deployments and Roll back deployments lets someone control runs and answer deployment gates without the rest of the editor role.
Some actions stay with admins and cannot be added to a custom role: managing members, roles and invitations, API keys, billing, integrations, organization settings, break-glass overrides, overriding a deployment decision made by a Block compliance policy, and overriding a release policy. Only a custom role with the admin base role includes them, and that gives full control of the organization.
Good to know:
- Changes to a role apply to its members within about five minutes.
- If your organization moves to a plan without custom roles, members keep the custom role's base role and lose the extra permissions until you upgrade again.
- Deleting a custom role removes it from its members. They keep their other roles, or become readers.
- The Users page shows what each member can actually do: the role they act as and any extra permissions.
- Creating, changing and deleting roles is recorded in the audit log.
- The admin console will not let a role change or deletion leave the organization without an admin.
Invite people and change roles
Invite people to your organization, choose their role, and manage members in the Admin Console.
Linked provider accounts
Link your own GitHub, GitLab, Bitbucket or Azure DevOps account so Prodgator can approve deployments and run stages as you, and see the accounts added from your sign-in or found by your email.