An admin role grants access to specific areas of the Administration menu. Admin roles are created and maintained under Administration > Teams & Roles > Admin Roles, and assigned to people on their user record.
💡 This means an administrator can be given exactly the areas they need at exactly the level they need, instead of a single broad grade of access.
The Admin Roles tab is visible to Full Admins only, and only a Full Admin can create, edit, delete or assign an admin role. A user with Read access or higher to Teams & Roles does not see the tab unless they are also a Full Admin.
See this article for a general overview of the Manage Users page.
Permission levels
Each area of Administration is granted at one of four levels:
- None — no access. The area does not appear in the Administration menu at all.
- Read — the area's page is shown with its controls disabled.
- Update — existing records can be edited.
- Full — records can be created and deleted as well as edited.
Not every area offers all four levels; some are limited to the levels that make sense for them. Integrations, for example, is offered as None or Update.
Where a user holds more than one admin role, the highest level granted for each area applies, as it does with other role permissions.
Permission areas
An admin role carries a level for each of the following areas:
- Hierarchy
- Manage Users
- Site Settings
- Mapping Techniques
- Classifications
- Measurement Units
- Custom Fields
- Custom Dashboards
- Notifications
- Teams & Roles
- Status Thresholds
- Ratings
- Amplify License
- Workflows
- Stage Gate Process
- Cost Group & Category
- User Views
- Translations
- Integrations
- Firewall & API
- Authentication
- Amplify Intelligence
A few areas behave in a particular way regardless of the level set against them:
- Amplify Intelligence appears as a permission area only where Amplify Intelligence is enabled for the instance. Where it is switched off, the setting held against each role is retained and only the row is hidden.
- Amplify License can be updated by Support users only, so it reads as view-only to others.
- Individual firewall rules cannot be edited; they can be deleted and re-added.
Where Hierarchy is set to None and the user holds no team member role granting access to initiatives, the hierarchy icon is hidden and the Administration Overview page becomes their landing page.
Creating an admin role
- Open Administration > Teams & Roles and select the Admin Roles tab.
- Click + Create New Admin Role. A side sheet opens.
- Give the role a name.
- Set the level for each permission area. A new role starts with Hierarchy set to Full and every other area set to None.
- Save.
Roles are listed alphabetically by name, with their permissions shown as columns. Full Admins can also change permission values directly in the table.
Editing and deleting an admin role
Click the pencil icon on a role's row to open it in a side sheet. Side sheets are addressable by URL, so a link to a particular role can be shared.
The trash icon deletes a role. It is available only where the role is not assigned to any active user, so a role in use must be unassigned from those users first.
Assigning an admin role to a user
- Open Administration > Manage Users and open the user.
- Make sure Grant this user Full Admin Privileges is not selected. While it is, the Assign this user an Admin Role setting is hidden — any roles already assigned are retained and reappear if the checkbox is cleared again.
- Open Assign this user an Admin Role and select one or more roles. Roles are listed alphabetically, and a role already selected is not offered again in the list.
- Save.
The Admin Roles column on the Manage Users table lists the roles held by each user alphabetically, separated by commas — for example Business Admin, Technical Admin. Full Admins show as Full Admin.
Admin roles are assigned on the user record only. They are not available as approver roles and cannot be assigned to an initiative team.
Granting administrative access is reserved to Full Admins. A user with Update or Full access to Manage Users can manage users but cannot grant Full Admin privileges, assign an admin role, or grant System Settings or Support privileges.