Custom roles
Build a role from a built-in base role and extra permissions, and what stays with Org admins.
Availability
Who can use this: Org admin only. See Roles.
A custom role starts from a built-in base role (Viewer, Developer, Release manager, Security, Compliance or Org admin; see Roles) and can add extra permissions from the list below. Members with the role can do everything the base role can, plus the extra permissions. A custom role never takes permissions away: to give someone less, pick a base role that holds less. The list shows which built-in roles already include each permission, so a permission already in the base role cannot be added again.
| Permission | Included in | What it allows |
|---|---|---|
| Cancel runs | Developer, Release manager and Org admin | Cancel GitHub Actions, GitLab, Bitbucket and Azure Pipelines runs that are still running. |
| Re-run runs | Developer, Release manager and Org admin | Re-run failed jobs of finished GitHub Actions, GitLab and Azure Pipelines runs, and re-run one finished GitHub Actions or GitLab job. |
| Read failure logs | Developer, Release manager, Security and Org admin | Read the logs of failed runs and jobs. |
| Generate AI results | Developer, Release manager, Security, Compliance and Org admin | Ask for AI summaries and explanations. |
| Work with Jira issues | Developer, Release manager, Security, Compliance and Org admin | Create, link and unlink Jira issues. |
| Inspect policies | Developer, Release manager, Security, Compliance and Org admin | Open the evaluation details and results of a release policy. |
| Re-check pull requests | Developer, Release manager, Security, Compliance and Org admin | Run the release policies again on a pull request. |
| Upload security reports | Developer, Release manager, Security and Org admin | Upload scanner reports and start Wiz or Snyk connector syncs. |
| Approve pull requests | Release manager and Org admin | Approve a pull request that is waiting on a release policy. |
| Approve deployments | Release manager and Org admin | Approve, reject and re-evaluate deployment gates. |
| Roll back deployments | Release manager and Org admin | Start a rollback to an earlier deployment. |
| Override release policies | Release manager and Org admin | Let a deployment or pull request through although a release policy failed. |
| Edit release policies | Release manager and Org admin | Create, edit, import and bind release policies. |
| Edit approver groups | Release manager and Org admin | Create and edit approver groups. |
| Edit gates | Release manager and Org admin | Create and edit gates and the deployment environments they link. |
| See the member list | Release manager and Org admin | See member names and emails, for example to pick approvers. |
| Manage custom adapters | Release manager and Org admin | Create and edit custom adapters and processing rules. |
| View SPACE metrics | Release manager and Org admin | Open the SPACE developer metrics. |
| Share AI widgets | Release manager, Security, Compliance and Org admin | Share AI widgets with the organization and edit shared ones. |
| Export data | Release manager, Security, Compliance and Org admin | Start data exports and download them. |
| View enforcement | Release manager, Security, Compliance and Org admin | See enforcement decisions, settings and break-glass overrides. |
| Run compliance evaluations | Release manager, Compliance and Org admin | Start a compliance evaluation. |
| Triage security findings | Security and Org admin | Dismiss, reopen, split and rejoin alerts, scan results and findings. |
| Manage tracked branches | Security and Org admin | Choose which branches are scanned and tracked for security findings. |
| Manage security connections | Security and Org admin | Connect and disconnect security scanning platforms. |
| Manage compliance policies | Compliance and Org admin | Turn policies on or off, set enforcement modes and settings, and re-evaluate decisions. |
| Answer a deployment that a Block compliance policy governs | Compliance and Org admin | Approve or reject it with a stated reason. |
| Create break-glass overrides | Compliance and Org admin | Skip a compliance block in an emergency. Each override is recorded. |
| Read the audit log | Compliance and Org admin | Open the audit log of changes to members, roles and settings. |
For example, a "Release approver" role based on Developer with Approve deployments and Roll back deployments lets someone control runs and answer deployment gates without the rest of the Release manager role.
Grants can include the compliance and audit permissions too, such as Create break-glass overrides and Read the audit log, so a custom role can give a person one of those without the full Compliance role.
Some actions stay with Org admin and cannot be added to a custom role: managing members, roles and invitations, identity settings (SSO, directory sync, domains and the break-glass admin), API keys, billing, integrations other than security platforms, organization settings, and the settings that let Release managers override release policies. Only a custom role with the Org admin base role includes them, and that gives full control of the organization.
A member can hold several roles, built-in and custom, and gets what any of them allows.
Good to know:
- Changes to a role apply to its members within about five minutes.
- If your organization moves to a plan without custom roles, members keep the custom role's base role and lose the extra permissions until you upgrade again.
- Deleting a custom role removes it from its members. They keep their other roles, or become Viewers.
- Organization > Members shows what each member can actually do: the roles they hold and any extra permissions.
- Creating, changing and deleting roles is recorded in the audit log.
- Prodgator will not let a role change or deletion leave the organization without an Org admin.
Invite people and change roles
Invite people to your organization, choose their roles, and manage members on the Organization page.
Linked provider accounts
Link your own GitHub, GitLab, Bitbucket or Azure DevOps account so Prodgator can approve deployments and run stages as you, and see the accounts added from your sign-in or found by your email.