Permissions and custom roles
Configure permission groups for durable enterprise responsibilities.
Configure permission groups for durable enterprise responsibilities.
Custom permissions are powerful because they can create exactly the access an organization needs. They also make access harder to explain unless the role has a durable purpose, owner, and review process.

Review Workspace, Projects, Annotation & Review, and Models & Data permission groups as a whole before saving a custom role.
Granular permissions include:
Workspace
manage workspace settings;
manage billing;
manage API keys;
manage cloud storage;
manage members.
Projects and schemas
manage projects;
manage ontologies;
assign project members;
manage releases;
view ontology;
view instructions;
manage instructions.
Annotation and review
view labeling interface;
create labels;
comment;
view statistics.
Models and data
manage data;
manage AI models;
manage workflows;
manage augmentation.
Use built-in roles when they meet the responsibility.
Name custom roles by durable job function, not a temporary person or ticket.
Document allowed and deliberately denied actions.
Test project, workflow, queue, model, data, and release behavior with a representative account.
Assign an owner and review date; remove roles that no longer have active members or purpose.
Continue with Unitlab: enterprise data annotation workflows