Use built-in roles to separate ownership, management, annotation, and review.
Built-in roles provide understandable starting points for least privilege. Effective access still depends on workspace, project, workflow, assignment, and resource state.
List the actions each persona needs and does not need.
Separate administrative ownership, operations management, annotation, and independent review.
Identify any sensitive data or model-management restrictions.

Review the effective capability across permission groups rather than relying on a role name alone.
Built-in roles include:
Owner;
Manager;
Member;
Annotator;
Reviewer.
Administrators can also create custom roles for workspace-specific access patterns.
Roles can be configured to permit assignment as an Annotator or Reviewer.
Workspace role and project position are different:
Workspace role controls tenant-wide capabilities.
Project position determines eligibility for annotator or reviewer workflow stages.
Owner, Manager, and custom roles use the administrative branch by default. Member, Annotator, and Reviewer are assignment-scoped and see only the stage queues and work items for which they are eligible.
Owner
Reserve for accountable workspace administration and recovery.
Manager
Use for operational management without unnecessary ownership rights.
Annotator
Limit to assigned annotation work and applicable collaboration.
Reviewer
Preserve independent review capability and avoid hidden conflicts.
Create a custom role only for a durable gap.
Document project and stage assignments.
Include role review in offboarding and production-readiness checks.
Explore related Unitlab capabilities: enterprise data annotation workflows