RRecords Labs Help Center

Roles and capabilities

What someone can do in Records Labs is set by capabilities, named permissions such as "Invite members & set roles" or "Approve & publish content". A role is a bundle of capabilities. Six built-in roles cover most organizations, and you can create custom roles when they do not.

Open Settings → Roles & Permissions and find What each role can do to see the full matrix: capabilities down the side, roles across the top, with a check for each grant. Switch between Built-in, Custom, and All to choose which roles appear as columns.

The capabilities

They are grouped the way the matrix shows them.

  • Use knowledge: Ask & read shared knowledge; Use assigned agents.

  • Create & contribute: Add sources & upload files; Draft articles & FAQs; Edit existing knowledge.

  • Review & publish: Approve & publish content; Moderate the review queue; Manage taxonomy & structured fields.

  • Govern & oversight: Set sensitivity & audience; Approve access requests; View audit log & activity; Run access reviews & attest.

  • Analytics & reporting: View own usage stats; View org analytics; View cost & budget; Export & schedule digests; Per-person usage drill-down.

  • Help Desk & live chat: View the live chat inbox; Respond to live conversations; View support reports; View own support stats.

  • Agents & skills: Create agents; Edit & manage agents; Delete agents; Create & configure skills; Grant skills to agents.

  • Configure: Build & configure widgets; Connect & remove sources; Manage connectors & credentials.

  • People & organization: Invite members & set roles; Invite & manage guests; Organization settings & security; Billing & plan; Transfer or delete the organization.

How the built-in roles map

Role

Summary of grants

Owner

Every capability, including Transfer or delete the organization.

Admin

Everything except transfer or delete. Runs people, sources, agents, settings, security, and billing.

Editor

All of Create & contribute and Review & publish. Limited grants to set sensitivity, create and manage agents, grant skills, and build widgets. Sees quality and support analytics.

Contributor

Add sources and draft notes. Cannot edit others' knowledge or publish.

Support

View and respond in the live chat inbox, see support reports and their own support stats. No knowledge editing.

User

Ask and read shared knowledge, use assigned agents, see their own usage.

A few cells in the matrix show a dot instead of a check. That is a limited grant: the role has the capability within a narrower scope, for example an Editor can create agents but cannot give them external access.

Data visibility is separate from capabilities. What a person can see is governed by their role's base, by teams, and by sensitivity rules under Knowledge → Access & policy. A capability lets you do something; it does not widen what you can read.

Custom roles

Create one when a built-in role is close but not right, for example a knowledge curator who can publish but should not touch agents, or an admin who cannot buy credits.

  1. Go to Settings → Roles & Permissions.

  2. Choose Create custom role, or choose Duplicate on an existing role to start from its grants.

  3. Enter a Name.

  4. Pick Based on. This sets the role's data visibility floor. It cannot be Owner, and it cannot be higher than your own role.

  5. Switch each capability on or off. A limited grant copied from a built-in role stays limited until you switch it off; switching a capability on always gives the full grant.

  6. Choose Create role (or Create copy when duplicating).

The new role appears in the Roles list and as a column in the matrix under Custom and All. To edit or remove it, open the menu on its row and choose Edit or Delete. Members on a deleted role fall back to the default role.

The role picker on the People page lists the built-in roles. New members get a custom role when you make it the default role for new members (see below).

Built-in roles cannot be edited. Duplicate one instead.

Change a member's role

  1. Go to Settings → People → Members.

  2. Use the role picker on the member's row, or click the row and change the role in their details.

Roles above your own authority are read-only. Owner cannot be assigned from the picker.

The default role

Default role for new members, at the top of Roles & Permissions, is the role people get when nobody picks one for them, for example when you approve a request to join under Settings → People → Requests. Single sign-on has its own role setting. SCIM has one too, but when it is left at Member, people provisioned by SCIM get this default role. See SSO and passkeys. Custom roles based on Admin, Editor, Contributor, Support, or User can be the default.

What super admins are not

Records Labs staff who operate the platform hold a super admin role. It is not a role you can assign, and nothing in your organization's settings depends on it. You will not find super admin in your Role picker, and the platform sections of Settings are not part of your organization's navigation. Your people and your data are governed by the roles above.

Was this article helpful?
Related articles
TeamsTeam & accessAPI changelogDevelopersAuthentication, keys and scopesDevelopersBrowser extensionDevelopers