Roles & permissions
Description
A role is a named set of permissions. Assigning a role to a user grants them exactly the
permissions the role carries — nothing more. This view is a read-only reference of Myra's
built-in system roles: admin, tenant_admin, ki_manager, finance, member, viewer,
demouser. To create your own delegated roles, see Custom roles.
The Roles & permissions view is the Roles & permissions tab of User Management,
reached from the user-block menu at the bottom of the left sidebar → User Management (route
/roles). It is visible to users who hold the Role-management permission (ROLE_MANAGE or
SYSTEM_ROLE_MANAGE — held by admin and tenant_admin, and by any custom role you grant it
to).
The list shows each system role with its permission count and how many of your tenant's users currently hold it. Every row carries a Managed by Myra lock hint instead of edit/delete actions — system roles cannot be edited, recomposed, or deleted.
The permission catalog
Permissions are grouped by module (chat, agents, workflows, projects, prompts, guardrails, governance, users, roles, finance, and so on). The catalog itself is used when building a custom role; this reference page does not expose it (nothing here is editable).
Assigning a system role
System roles are assigned as a user's base role on the Members view (or, for admin/
tenant_admin, on Platform admins) — not from this page.
See also
- Custom roles — creating and managing your own delegated roles.
- Members — assigning system roles to users.
- Platform admins — assigning
admin/tenant_admin. - Groups — granting scoped access at the group level.
- Roles API — the endpoints, the full permission catalog, and the delegation/subset/rank fences.