> For the complete documentation index, see [llms.txt](https://documentation.proto.cx/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.proto.cx/docs/settings/general/roles-and-permissions.md).

# Roles & permissions

Create and manage custom user roles and permissions in Proto AICX.

Roles define what actions users can perform in the workspace. Each user is assigned one role.

Go to **Settings → Workspace → Roles & Permissions**.

***

## Roles table

| Column      | Description                                 |
| ----------- | ------------------------------------------- |
| Name        | The role's display name                     |
| Description | Optional description of the role's purpose  |
| Type        | Workspace-wide or scoped to a specific team |

**Admin** is the only default role. It has full access to all workspace settings and modules and cannot be deleted.

***

## Create a role

1. Select **Create Role**.
2. Set the **Name**, optional **Description**, and **Type** (Workspace or Team).
3. Configure permissions by toggling each on or off.
4. Select **Create**.

{% hint style="info" %}
Role names must be unique. When you create or rename a role, the **Name** field shows an error if the name is already in use and the change isn't saved.
{% endhint %}

***

## Edit a role

1. Select the role in the table.
2. Update name, description, or permissions.
3. Select **Save**.

***

## Delete a role

{% hint style="warning" %}
The Admin role cannot be deleted, so it has no selection checkbox in the roles table.
{% endhint %}

1. Select one or more role checkboxes, or select the header checkbox to select every deletable role at once.
2. Select **Delete Role** and confirm.

The header checkbox only selects roles that have their own checkbox, so protected roles such as Admin are skipped automatically and are never included in a bulk delete.

{% hint style="info" %}
If the role is assigned to a team, deleting it does not delete the team. The team keeps its members, teamspaces, and subcompany assignments, but is left without a team role until you assign a new one. Team members keep their account and any other role or team assignments — they only stop receiving the permissions that came from that team's role.
{% endhint %}

***

## Related

{% content-ref url="/pages/NG0GzByDMsgTvO0gZwos" %}
[Users](/docs/settings/general/users.md)
{% endcontent-ref %}

{% content-ref url="/pages/Yv2FrW5BPJLhCpaj5fDx" %}
[Teams](/docs/settings/general/teams.md)
{% endcontent-ref %}
