ProdgatorDocs
Organization

Custom roles

Build a role from a built-in base role and extra permissions, and what stays with Org admins.

Pas encore traduite. Cette page est affichée en anglais. Lire l’original en anglais.

Availability

Business plan and above. Org admins create custom roles in Organization > Roles.

Who can use this: Org admin only. See Roles.

A custom role starts from a built-in base role (Viewer, Developer, Release manager, Security, Compliance or Org admin; see Roles) and can add extra permissions from the list below. Members with the role can do everything the base role can, plus the extra permissions. A custom role never takes permissions away: to give someone less, pick a base role that holds less. The list shows which built-in roles already include each permission, so a permission already in the base role cannot be added again.

PermissionIncluded inWhat it allows
Cancel runsDeveloper, Release manager and Org adminCancel GitHub Actions, GitLab, Bitbucket and Azure Pipelines runs that are still running.
Re-run runsDeveloper, Release manager and Org adminRe-run failed jobs of finished GitHub Actions, GitLab and Azure Pipelines runs, and re-run one finished GitHub Actions or GitLab job.
Read failure logsDeveloper, Release manager, Security and Org adminRead the logs of failed runs and jobs.
Generate AI resultsDeveloper, Release manager, Security, Compliance and Org adminAsk for AI summaries and explanations.
Work with Jira issuesDeveloper, Release manager, Security, Compliance and Org adminCreate, link and unlink Jira issues.
Inspect policiesDeveloper, Release manager, Security, Compliance and Org adminOpen the evaluation details and results of a release policy.
Re-check pull requestsDeveloper, Release manager, Security, Compliance and Org adminRun the release policies again on a pull request.
Upload security reportsDeveloper, Release manager, Security and Org adminUpload scanner reports and start Wiz or Snyk connector syncs.
Approve pull requestsRelease manager and Org adminApprove a pull request that is waiting on a release policy.
Approve deploymentsRelease manager and Org adminApprove, reject and re-evaluate deployment gates.
Roll back deploymentsRelease manager and Org adminStart a rollback to an earlier deployment.
Override release policiesRelease manager and Org adminLet a deployment or pull request through although a release policy failed.
Edit release policiesRelease manager and Org adminCreate, edit, import and bind release policies.
Edit approver groupsRelease manager and Org adminCreate and edit approver groups.
Edit gatesRelease manager and Org adminCreate and edit gates and the deployment environments they link.
See the member listRelease manager and Org adminSee member names and emails, for example to pick approvers.
Manage custom adaptersRelease manager and Org adminCreate and edit custom adapters and processing rules.
View SPACE metricsRelease manager and Org adminOpen the SPACE developer metrics.
Share AI widgetsRelease manager, Security, Compliance and Org adminShare AI widgets with the organization and edit shared ones.
Export dataRelease manager, Security, Compliance and Org adminStart data exports and download them.
View enforcementRelease manager, Security, Compliance and Org adminSee enforcement decisions, settings and break-glass overrides.
Run compliance evaluationsRelease manager, Compliance and Org adminStart a compliance evaluation.
Triage security findingsSecurity and Org adminDismiss, reopen, split and rejoin alerts, scan results and findings.
Manage tracked branchesSecurity and Org adminChoose which branches are scanned and tracked for security findings.
Manage security connectionsSecurity and Org adminConnect and disconnect security scanning platforms.
Manage compliance policiesCompliance and Org adminTurn policies on or off, set enforcement modes and settings, and re-evaluate decisions.
Answer a deployment that a Block compliance policy governsCompliance and Org adminApprove or reject it with a stated reason.
Create break-glass overridesCompliance and Org adminSkip a compliance block in an emergency. Each override is recorded.
Read the audit logCompliance and Org adminOpen the audit log of changes to members, roles and settings.

For example, a "Release approver" role based on Developer with Approve deployments and Roll back deployments lets someone control runs and answer deployment gates without the rest of the Release manager role.

Grants can include the compliance and audit permissions too, such as Create break-glass overrides and Read the audit log, so a custom role can give a person one of those without the full Compliance role.

Some actions stay with Org admin and cannot be added to a custom role: managing members, roles and invitations, identity settings (SSO, directory sync, domains and the break-glass admin), API keys, billing, integrations other than security platforms, organization settings, and the settings that let Release managers override release policies. Only a custom role with the Org admin base role includes them, and that gives full control of the organization.

A member can hold several roles, built-in and custom, and gets what any of them allows.

Good to know:

  • Changes to a role apply to its members within about five minutes.
  • If your organization moves to a plan without custom roles, members keep the custom role's base role and lose the extra permissions until you upgrade again.
  • Deleting a custom role removes it from its members. They keep their other roles, or become Viewers.
  • Organization > Members shows what each member can actually do: the roles they hold and any extra permissions.
  • Creating, changing and deleting roles is recorded in the audit log.
  • Prodgator will not let a role change or deletion leave the organization without an Org admin.