A role bundles a set of permissions and hands them to each person who holds it. The Roles screen is where you build those bundles — naming each role and deciding what it can do across your site.
The roles screen
The Roles screen sits in the Policy area of Setup, under the "Roles" tab. It splits into two halves: a list of your existing roles on one side, and the details of whichever role you select on the other.
Find a role with the "Search roles" box, then select it to open its details. Each entry in the list shows the role's name, a short key such as admin, and how many people hold it. To begin a fresh role, select "New role".


The details panel holds the role's "Name", an optional "Description", the permissions it grants, and a "Members" section listing who holds it. "Delete" removes the selected role. The "Save changes" and "Discard" buttons stay inactive until you make an edit; once you change something, "Save changes" keeps it and "Discard" drops it.
To create a role:
- Select "New role".
- Enter a "Name", and a "Description" if it helps others understand the role.
- Choose the permissions the role should grant.
- Select "Save changes".
For adding and removing the people who hold a role, see members.
Granting permissions
A role's permissions decide what its holders can do. Instead of one long flat list, the screen groups permissions by area — such as Reporting, Automation and Administration — so you can grant a whole area at once or set individual permissions within it.
Each area has a "Grant everything in …" checkbox that turns on every permission inside it. Open an area to see and set its permissions one by one. The "Filter permissions — names, descriptions or keys" box narrows the list to matching permissions, and "Expand all" and "Collapse all" open or close every area together.
A permission applies to a whole type of thing — the whole directory, every report, every page — rather than a single item. Granting a role permission to edit reports lets its holders edit any report, wherever it sits. To give one person access to a single part of the directory or one page instead, use sharing, covered in access and sharing and the sharing screen.
The "What this role grants" summary keeps a plain-language readout of where the role ends up — each area followed by its level, such as "full access". Use it to review a role before you save. For the full list of permissions and what each one controls, see the roles and permissions catalogue.
Inheriting permissions from other roles
A role can build on others through the "Inherits from" field. As the screen puts it, "This role gains every permission of the roles it inherits. Highest permission always wins." A role that inherits another starts with everything that role grants, and you add to it from there — which keeps a family of related roles in step without repeating the same choices. For the wider picture of how roles shape access, see roles and permissions.
Screen access
The Roles screen carries real weight: a saved change reshapes what people can do across your whole site. Reaching it depends on your own role — you need one that grants access to the Policy area of the Setup area. Someone without that access still reaches Pyron's other screens, but not this one.
A change applies to each person holding the affected role the moment you save it. Before saving a change to a role people already hold, review the "What this role grants" summary and its member list so the resulting access matches what you intend.