Default system roles
Klaritics includes predefined roles covering common organizational use cases.Custom roles
Organizations that need roles tailored to internal workflows can create custom roles from a configurable permission catalogue. Custom roles are created at organization level. Every custom role is:- Visible across all applications and projects within the organization
- Reusable across those applications and projects
Create a custom role
1
Define role details
Provide the role’s identifying information.
For example: Role Name
Marketing Analyst, Description Can build marketing dashboards, Scope Project.2
Configure permissions
Select permissions from categorized groups. You can enable or disable each permission for the role.
3
Review the role preview
Before saving, review a summary of what the role grants and restricts.
4
Save the role
Once saved, the role becomes available for assignment.
Role actions and status
The roles list includes a status column. A role is either active or deactivated.
Who can assign which roles
Role assignment is governed by hierarchy.Custom role behavior
A user holding a custom role can assign that same custom role, and can assign other roles created by a user with that custom role. Example User A holds the custom roleMarketing Lead. They can assign Marketing Lead, and roles created by User A.
They cannot assign Admin unless the hierarchy permits it.
Multiple roles per user
Users may inherit roles from more than one source:- Organization role
- Team membership
- Individual assignment
Marketing Analyst and Executive Viewer. Klaritics combines these permissions during access evaluation.
Conflict resolution
When a user inherits multiple roles, permission conflicts can occur. Klaritics always resolves them the same way: the highest level of access among the assigned roles is granted.There is no alternative resolution mode to configure. The most permissive role always wins.
Removing users
Removal follows the same hierarchy as assignment.- Admin can remove Editors and Viewers
- Editor can remove Viewers
- Viewer cannot remove anyone
Next steps
- Users to invite team members and manage their status
- Dashboard and chart permissions for resource-level access within a project