Created with AI.
Custom roles should be created sparingly and with care. This guide shows the approach for creating a role you can maintain through upgrades.
Never build from scratch. Copy the standard role that most closely matches your needs and adjust it. This gives you a well-designed starting point and avoids having to discover missing permissions one by one in production.
Write down which tasks the person will perform before assigning permissions. The role should reflect a function within the organization, not an individual person.
Choose between your own entries, those of your unit, those of subordinate units, or those of the entire organization. This is the very core of the model—spend time on this rather than on the details.
Start with restrictive permissions. It is far easier to add a permission someone needs than to discover that half the organization has seen something they should not have.
Create a user who only has this role, and go through the actual tasks. Do not test as an administrator—it always gives the green light.
Explain why the role exists and who it is for. Two years from now, this will be the difference between a role that can be maintained and one that no one dares to touch.
Ask a question or share what helped you.

Published 3/28/2025
We work continuously to improve information security (ISO 27001), quality (ISO 9001), and environmental management (ISO 14001), and are therefore proud to have successfully completed a new audit of our certifications in these areas.
Read morePublished 8/30/2024
Over the past few years, hybrid workplaces have become the norm for many. Along with this shift, both IT functionality and security needs have changed. Here are some useful tips from our Head of IT and Security on how organizations should approach securing their IT in a hybrid world.
Read moreDo you have a question or experience to share?
Be the first to contribute.