VeroXM Docs

Users & Roles

Every person with dashboard access to a project holds a role that determines what they can see and change. Built-in role tiers - Admin, Department Admin, Tenant Admin, Super Admin, and Developer - each carry a fixed bundle of permissions.

Custom roles

Departments can define custom roles with a specific set of permission grants (for example, a role that can manage API tokens and webhooks but not invite other users), then assign that role to individual users. A custom role's grants can be revoked per-user without deleting the role itself. See Departments for how custom roles are configured, and Approval Workflows for how a custom role can also be named as a required approver on a workflow step.

Inviting collaborators

Invite someone by email from Users & Roles; they receive an invitation and set their own password on first sign-in. Until accepted, an invitation can be revoked.

Permission-gated actions

Some actions are gated on a specific permission rather than a whole role tier - issuing API tokens and managing webhooks both require the api-tokens:manage permission, which every built-in admin-tier role holds and which can also be granted through a custom role.