Build, change and remove permission. All of the actions outline in this article are firm administrator tasks, performed in Settings → People.
Before you start
You need People → Admin in your own permissions to do anything on this page. That access level is what gates managing permissions at all. Also note that you cannot change your own staff profile’s user permissions.
Create a permission set
Build a new reusable permission set that you can attach to a role, or to an individual staff member.
- Select Settings in the sidebar, then People, then the Permission Sets tab. Every set in your firm is listed here, including the built-in Super Admin set.
- Select + New Permission Set.
- Enter a Name.
- Enter a Description. Optional in the form, but record what the set is for and any restrictions it carries — it is the only thing telling whoever manages permissions after you what this set was meant to do.
- Set an access level for each product section: No Access, Viewer, Editor, Admin or Custom.
- Selecting Custom unlocks that section's individual permission checkboxes so you can pick them by hand.
- Selecting any other level pre-fills those checkboxes and greys them out. You cannot adjust them individually.
- Select Save.
The set appears in the Permission Sets list and in the Permission Set dropdown on any role. It grants nothing to anyone until you assign it.
There is no one-click duplicate. To base a new set on an existing one, open the set you want to copy, note its access levels, then create a new set and configure it to match.
Edit a permission set
Change what an existing permission set grants. This changes access for everyone assigned to this permission set, either directly or through their role.
- Before changing anything, identify who uses the set. Go to Settings → People → Staff and note every staff whose Permission Set is the one you are about to edit. Every staff member assigned to the permission set is affected.
- Go to Settings → People → Permission Sets and select Edit next to the set.
- Adjust the Name or Description if needed.
- Change the access level for any product section.
- Switching a section to Custom lets you select individual permissions with the checkboxes.
- Switching a section from Custom to No Access, Viewer, Editor or Admin replaces the hand-picked selection with that level's fixed pattern.
Inferred, not published— the source states only that the checkboxes are pre-filled and greyed out at those levels. If this is right it is a data-loss branch and must be confirmed before publication.
- Select Save.
- Spot-check the result. Go to Settings → People → Staff, open a staff member with the permission set, and confirm the permissions panel shows the access you intended.
- Assigned permissions apply immediately, though currently signed in users may need to refresh their browser so that the updated permissions apply.
A staff member with an individual override is not brought back into line by this edit. Their override still takes priority, and their Permission Set label reads Custom because they diverge from the set. See Fix a staff member whose permissions did not change with their role.
Delete a permission set
Remove a permission set your firm no longer uses.
What happens to anyone still on it. Staff assigned to the deleted set fall to the next level of the hierarchy: a staff member with an override keeps the override, a staff member whose permission set pointed at the deleted set falls to the firm default, and the firm default is basic viewing. Nobody is locked out, but people can quietly lose access they had yesterday.
The Super Admin set cannot be deleted. It is the firm's guaranteed full-access fallback, which is why a firm cannot lock itself out of its own portal by deleting sets.
- Go to Settings → People → Staff and note every person still pointing at the set. For each, select Edit, choose a different Permission Set, and select Save.
- Go to Settings → People → Permission Sets.
- Under the Actions column, select the three small dots and select Delete…
- Read the warning and confirm.
Add a role
Create a role your firm can assign to staff and attach a permission set to.
- Go to Settings → People → Roles.
- Select New Role....
- Enter a name and a description.
- Leave the row. Changes save automatically — there is no Save button on this grid.
- Assign a permission set before you put anybody in the role. A role with no permission set grants nothing of its own, so staff placed in it resolve to the firm default by accident.
Assign a permission set to a role
Attach a permission set to a role so that every staff member holding that role inherits it. This is the recommended route: set it once on the role, and people joining that role next year inherit it too.
The Permission Set dropdown offers only sets that already exist, and you cannot pick individual permissions here. If the set you need does not exist, create it first.
- Go to Settings → People → Roles.
- Select Edit next to the role you want to update.
- Select a Permission Set from the dropdown.
- Select Save.
Every staff member with that role now inherits the set's access levels — unless an individual override is set on their profile.
Remove a role
Remove a role definition from your firm.
- Go to Settings → People → Roles.
- Right-click the role's row and select Remove.
- Confirm.
Related
- How permission resolution works
- Access levels and what each one grants
- Override one staff member's permissions
- Fix a staff member whose permissions did not change with their role
- Check a staff member's effective permissions
- Built-in permission set reference
- Add a staff member