Note: the built-in help tip mentioning an "Everyone" role is stale — no such role exists by default; the three seeded roles are Members, Team Members, and Administrator (Full Access).
Create a role, or adjust an existing one's rights, description, or session timeout.
Before you start
The Configure System right (gates this entire Essential Setup section).
Steps
Create a role
- Go to Settings → Essential Setup → Security Roles.
- Click Add Role.
- Enter a Role Name (required, 2–50 characters) and an optional Description.
- Optionally set a Session Timeout (minutes) — leave blank to inherit the default.
- Assign rights: expand the General Permissions group, plus one group per app your organization has enabled (CRM, HRS, Docs, etc.), and the always-present Access Security, Accounting & Finance, and Administration groups. Set each right to Granted, Not Specified, or Nuke.
- Use the search box (appears once a group has more than 8 rights) to jump to a specific right — matches keep their parent rights visible for context.
- Use a parent right's grant branch / revoke branch buttons to set its whole subtree at once, instead of clicking every child individually.
- Click Save.
Edit or delete a role
- Click a role to edit it the same way. System roles may have their name and/or rights locked — a locked field is disabled with an explanation.
- Click Delete to remove a custom role. Confirm: "Are you sure you want to delete the security role '{name}'? This will remove all associated permissions and cannot be undone." System roles marked non-deletable can't be removed this way.
What you'll see
Granting or denying a right automatically cascades to its parents/children in the same action, with an undo toast telling you exactly what else moved. See Security Roles Explained for how a role's rights combine with Department, Job Title, and member-level overrides into a member's actual effective permissions.
Related articles
Other guides that answer questions close to this one.
Security Roles Explained
This closes a question deferred from the CRM documentation: "How do I control which users can see which leads (RBAC/territory)?" There's no territory concept anywhere in the product — visibility is entirely…
How to Assign a Role to a Member
Note: this doesn't happen from Security Roles, Departments, or Job Titles — role assignment to an actual person is done on that person's own member settings page. Give a specific team member one or more roles, and…
How to Create and Manage Departments
Build out your organization's department structure, and optionally grant departments their own roles or rights on top of what their members' roles already give them. Before you start The Configure System right. Steps 1.…