How can I create new roles?
The screenshots in this article show the German interface. Where a button or field matters, the German label is given in brackets so you can match text to screenshot.
Roles decide which contract categories a person can see and edit. This article shows you where roles live, how to set an access level per category, and how to assign a role to a team member.
What's in it for you
A cleanly built role structure cuts your admin workload and your security risk at the same time: new joiners get the right view of the right contracts from day one, a move between departments is handled with a single click, and sensitive content (employment contracts, M&A, data processing agreements) stays limited to the people who actually need it — which matters for GDPR, internal compliance and audits.
How it works
1. Open the roles area
Go to Settings („Einstellungen")

Then go to Organisation → Organisation details („Organisation → Details zur Organisation") and scroll down the page to the "Member roles (X)" („Mitgliederrollen (X)") card, subtitled "Set and manage roles to control organisation access" („Rollen festlegen und verwalten, um Organisationszugriff zu steuern"). Here you see every role that already exists in your account.
2. Create a new role
On the right-hand side of the card, click "+ Add new role" („+ Neue Rolle hinzufügen").

The "Role" („Rolle") dialogue opens.
Fill in:
- New role name („Neuer Rollenname") — mandatory. Use a name that makes the purpose of the role obvious: "Finance read", "Legal full access", "Sales leases". Generic names such as "Role 1" only cause confusion later.
- Select team („Team auswählen") — mandatory. Roles apply per team. Choose the team this role should apply to. If you have several teams and need the same role in more than one of them, you have to create it separately for each team.

3. Set the access level per category
Below the role name you will find a table listing every contract category in your account. For each category you choose one of three access levels using radio buttons:
- Full access („Voller Zugriff") — members with this role can see AND edit contracts in this category (change fields, adjust the status, and delete where applicable).
- Read only („Nur Lesen") — members can see the contracts in this category but cannot make any changes. Useful for stakeholders who only need to stay informed.
- No access („Kein Zugriff") — the default. Contracts in this category are not visible at all to members with this role, not even greyed out. They appear in no list, no search and no report.
Set the access level you want for every category. For example, a "Finance read" role might be set to Full access for financing and loan agreements, No access for employment contracts, and Read only for everything else.
4. Save the role
Click "Create" („Erstellen"). The role appears in the member roles list immediately and can be assigned to new invitations or to existing members from that point on.

5. Assign the role to a member
When you invite new members, or on the detail page of an existing member, pick the role from the "Select roles" („Rollen auswählen") dropdown. One person can hold several roles — their access adds up as the union of everything those roles allow.
Common questions
Who is allowed to create roles?
Only members with owner status in the organisation. Regular members can see the "Member roles" („Mitgliederrollen") area but cannot create new roles. Regular members do, however, get full access to any category the owner creates at a later point.
What happens if I change a role afterwards?
The changes take effect immediately for everyone holding that role. Example: you take away a role's access to "Employment contract" — the affected members lose sight of employment contracts with their next page refresh.
Can several roles on one person contradict each other?
Where access overlaps, the more generous permission wins. If role A is set to "Read only" for NDAs and role B to "Full access", a person holding both roles gets full access to NDAs. "No access" always loses as soon as any assigned role allows access.
What do I need "Read only" for?
Classic use cases: a supervisory board that reviews contracts but should not change anything. Accounting, which looks at the figures but does not edit contract text. Auditors or external advisers with time-limited access.
Can I delete a role again?
Yes — you can remove a role from the "Member roles" („Mitgliederrollen") list. People who held that role and no other lose their access along with it. People with further roles keep the access those roles grant.
How do roles differ from teams?
Both control visibility. Teams represent organisational units (Finance, Legal, Procurement) and are where contracts are assigned centrally. Roles define what a person may see and do inside a team. Together they form the permission model: team = where, role = what.
Good to know
- Roles are per team, not per account. If you have several teams, you may need to create the same role more than once — once per team. Taking that into account early avoids confusion later.
- The default is "No access". When you create a new role, every category starts on No access („Kein Zugriff"). That is the security-conscious default, but it costs a few clicks per role — with long category lists it pays to have a clear concept before you start.
- A clear naming convention pays off. A format like "[Department] [access type]" (for example "Finance full access", "Legal read") makes assigning roles much faster, especially once you have 20 or more of them.
- Owners do not need a role. Members with owner status automatically have full access to all categories and all teams — no additional role is required.
- Start with a small number of roles. Five well-defined roles beat thirty near-identical ones. You can always add roles as the organisation grows, but the initial model should stay manageable.
Related articles
- What is the Advanced Permission Concept (APC)?
- What is the purpose of sub-teams, and how are they managed?
Updated on: 08/26/2026
Thank you!
