Custom User Roles
Create workspace roles with specific permissions for records, fields, lists, tags, forms, activity, and invitations.
Custom user roles let Project Administrators apply one permission set to people with the same workspace responsibilities.
Choose role permissions
For each role, you can:
- Apply the same permissions to multiple people.
- Control access to workspace activity and forms.
- Limit record visibility to records assigned to the user.
- Allow or deny record access based on tags.
- Control whether users can invite new members into the same custom role.

Control custom field access
Custom fields are visible and editable by default when you create a custom role. In Field Permissions, clear Edit to make a field read-only, or clear View to hide it. Computed fields remain read-only.

Control list access
Set view, edit, and delete permissions separately for each list in the workspace.

Control list structure
Use Create Lists to control whether the role can add lists. Use Edit Lists to control whether the role can rename and reorder lists. Use each list’s View, Edit, and Delete checkboxes to configure access to that list.
Control record actions
Configure these record permissions separately:
- Create Records: Control whether the role can add records to the workspace.
- Delete Records: Control deletion separately from editing. A role can edit records without permission to delete them.
- Delete Files and Folders: Control whether the role can remove file attachments or folders from the Files tab.
- Restrict Record Completion: Prevent the role from marking records as complete. Use this when a reviewer must control completion.
For example, an Editor role can prepare a record while a Publisher role completes it.
Control default field access
Use Field Permissions to choose View and Edit access for due dates, assignees, tags, descriptions, dependencies, checklists, time tracking, linked workspaces, and audit fields.
Audit fields such as Created at, Updated at, Completed at, and Last updated by are read-only. Clearing View also prevents editing.
Control access by tag
Tag-level permissions control which records a role can view and use. Choose allowed tags or denied tags for the role.
- Allowed Tags: Users can view only records with at least one specified tag.
- Denied Tags: Users can view all records except records with any specified tag.
Blue filters records automatically according to the configured tag permissions.
Allowed tags example
Set allowed tags to “Marketing” and “Sales.” Users can view records with either or both tags. Blue hides all other records.
Denied tags example
Set denied tags to “Confidential” and “Internal.” Users can view records with no tags or other tags. Blue hides records with either denied tag.
Create a custom role
- Enter a name that describes the role.
- Add an optional description.
- Select the permissions for the role.
The permissions control what users can view, edit, or delete. They can include access to workspace activity, forms, and custom fields.
Assign a custom role
Assign the custom role to individual workspace members. Blue applies the configured permissions to each member assigned that role.