> For the complete documentation index, see [llms.txt](https://docs.unitlab.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.unitlab.ai/documentation/collaboration/permissions-and-custom-roles.md).

# Permissions and custom roles

Custom permissions are powerful because they can create exactly the access an organization needs. They also make access harder to explain unless the role has a durable purpose, owner, and review process.

![Permission groups and custom role controls](https://292810646-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FGjVLUz4wthGkGlRKM6rM%2Fuploads%2Fae9ur8IvUdY0Oj98kTAD%2Froles-permissions.png?alt=media\&token=605e99b1-c6d9-4642-8d2f-b724c50790ab)

*Review Workspace, Projects, Annotation & Review, and Models & Data permission groups as a whole before saving a custom role.*

Granular permissions include:

**Workspace**

* manage workspace settings;
* manage billing;
* manage API keys;
* manage cloud storage;
* manage members.

**Projects and schemas**

* manage projects;
* manage ontologies;
* assign project members;
* manage releases;
* view ontology;
* view instructions;
* manage instructions.

**Annotation and review**

* view labeling interface;
* create labels;
* comment;
* view statistics.

**Models and data**

* manage data;
* manage AI models;
* manage workflows;
* manage augmentation.

### Use this in production

* Use built-in roles when they meet the responsibility.
* Name custom roles by durable job function, not a temporary person or ticket.
* Document allowed and deliberately denied actions.
* Test project, workflow, queue, model, data, and release behavior with a representative account.
* Assign an owner and review date; remove roles that no longer have active members or purpose.
