Docs menu
Roles & Access Administration
Simple default roles, with a fully custom model underneath.
Every workspace has a simple default (Viewer/Editor/Admin) and a fully custom model underneath it, for teams that need finer control.
The model
Three layers, from individual permission to person.
- Access rights — individual, named permissions (e.g. the right to view an audit trail, or approve a transfer)
- Access configurations — named bundles of access rights, functioning as custom roles
- Assignment — a configuration is assigned to a specific person
Viewer, Editor, Admin covers most teams.
Most workspaces never need more than the three starting roles from Getting Started — Viewer, Editor, and Admin. They're simple defaults, not a ceiling.
Custom configurations for regulated, role-specific access.
For teams that need finer-grained control — a QA Auditor who can only export audit trails, a Custodian who can only approve custody transfers — custom access configurations give you that precision. See the Configuration Guide's role → access-rights mapping for the exact rights used in Sample Management.
What's in the admin console today
AvailableAvailable in the admin console today.
- Create and manage individual access rights
- Bundle rights into named, reusable access configurations
- Assign configurations to individual users
- Every assignment and change captured in the audit trail