Skip to content

Roles ​

Feature Overview ​

ItemContent
Applicable RoleOperator
Navigation pathSettings > Members & Roles > Roles
Page route/user/user-space/roles
Managed objectsRole names, role identifiers, permission scopes, and creation times

Beginner Explanation ​

Operator roles are platform-console permission templates. They define which system modules an administrator can view, which settings the administrator can change, and which approvals the administrator can process. They are different from project collaboration roles.

Terms Quick Reference ​

TermDescription
Platform roleA set of operator-administration permissions.; Separate roles by responsibility.
PermissionA menu, button, or API-level control item.; Confirm the impact before changing it.
Built-in roleA system-provided role that usually cannot be deleted.; View it or use it as a reference.
Member assignmentThe operator members assigned to a role.; Remove assignments before deleting the role.

Prerequisites ​

  1. The current account has permission to manage roles.
  2. You have opened Members & Roles > Roles.
  3. Before authorizing or deleting a role, you have confirmed which members will be affected.

Page Description ​

The page provides the role list and role actions for creating, editing, authorizing, and removing permission templates.

Roles

AreaDescription
Role NameFilters roles by name.
Add RoleOpens the role creation flow.
Role tableShows role name, identifier, description, creation time, and actions.

Main Operations ​

View Roles ​

  1. Go to Settings > Members and Roles > Roles.
  2. Filter by role name, status, or update time.
  3. Open details and check menu, button, and API permissions and assigned members.
  4. If no record is returned, reset filters. For unexpected permissions, check whether the member has multiple roles.

Add a Role ​

  1. Go to Settings > Members & Roles > Roles.
  2. Click "Add Role" in the upper-right corner of the page.
  3. In the Add Role dialog, review the role creation fields.

Add Role

  1. Fill in Role name.
  2. Fill in the required Role code. Use a stable, readable, lowercase English code that is easy to audit.
  3. Fill in Role description according to the intended role usage.
  4. Before clicking the final Confirm, verify that the role name, role code, and later authorization scope follow the least-privilege principle.
  5. For learning or screenshots only, view the fields and click "Cancel" to close the dialog without submitting real role configuration.

Edit a Role ​

  1. Open Settings > Members & Roles > Roles.
  2. Locate the target Roles and click "Edit".
  3. Review or complete the required fields shown on the page, and confirm the target object, scope, and current status.
  4. For an action that changes data, permissions, status, or an external setting, confirm the impact and rollback path before clicking the final confirmation button.
  5. After the action, return to the list or details page and verify the status, update time, or result message.

Authorize a Role ​

  1. Open Settings > Members & Roles > Roles.
  2. Locate the target Roles and click "Authorize".
  3. Review or complete the required fields shown on the page, and confirm the target object, scope, and current status.
  4. For an action that changes data, permissions, status, or an external setting, confirm the impact and rollback path before clicking the final confirmation button.
  5. After the action, return to the list or details page and verify the status, update time, or result message.

Delete a Role ​

  1. Open Settings > Members & Roles > Roles.
  2. Locate the target Roles and click "Delete".
  3. Review or complete the required fields shown on the page, and confirm the target object, scope, and current status.
  4. For an action that changes data, permissions, status, or an external setting, confirm the impact and rollback path before clicking the final confirmation button.
  5. After the action, return to the list or details page and verify the status, update time, or result message.

Parameter Quick Reference ​

Field NameRequiredField TypeExampleDescription
Role nameYesTextAudit AdminThe display name of the operator role.
Role codeYesTextaudit_adminThe unique role identifier. Use a stable, readable code that is easy to audit.
Role descriptionNoTextView audit logs and basic operator informationDescribes the role purpose and authorization boundary.
Permission itemsYesMulti-selectView Operation LogsControls menus and operations available to the role.
Member countNoNumber3Shows how many members are bound to the role.
Role statusNoEnumEnabledControls whether the role can continue to be assigned.
ActionsSystem generatedButton / linkEdit / Authorize / DeleteProvides role maintenance entry points.

Pitfalls ​

  • Do not change roles, members, login policies, Keys, or API rate-control rules without confirming the affected users and systems.
  • UI entries can differ by role and tenant scope; verify the current account context before troubleshooting.
  • Never copy complete Keys, AK/SK, tokens, or secrets into documentation, tickets, or screenshots.
  • Adding a role creates a new platform permission template. Later authorization and member binding can affect platform management permissions.
  • Confirm is the final submit action. For learning or screenshots, only view fields and use Cancel to exit.
  • Once Role code is referenced, later changes may affect permission identification, auditing, and automation configuration.
  • Do not write real internal role codes, accounts, member IDs, customer names, or internal test data.

Result Validation ​

Check ItemSuccess SignalIf Abnormal
Role filterThe list refreshes by role name.Check that the name is correct.
Authorization entryThe target role can open its authorization page.Check the current account's role-management permission.
Delete entryDelete is displayed according to permission.Confirm that no critical member depends on the role before deletion.
Add dialogClicking Add Role opens the same-name dialog.Check whether the current account has role creation permission.
Cancel exitClicking Cancel closes the dialog without submitting role configuration.Refresh the page and confirm no test role was added.

FAQ ​

A member cannot see a menu ​

Symptom:

A member cannot see a menu or button after signing in.

Possible cause:

The role assigned to the member does not include the required menu or action permission.

Resolution:

Review the permission scope for the role, then confirm that the member is assigned to the correct role.

Can a role be deleted directly? ​

Symptom:

The role list provides a Delete action.

Possible cause:

The role may still be assigned to members, and deleting it can remove their access.

Resolution:

Check the members assigned to the role, then follow the tenant permission-change process.

Why is the operator role list empty? ​

Symptom:

The page does not show platform administrator, auditor, or configuration administrator roles.

Possible cause:

The current account lacks operator role-management permission, the roles belong to another administration tenant, or system roles cannot be edited in the list.

Resolution:

Confirm that you are using operator-side Settings and verify the role-management permission. Ask a super administrator to check abnormal built-in roles.

How should the Roles page be exported or captured safely? ​

Symptom:

Page information is needed for troubleshooting, audit, or delivery.

Possible causes:

The page may contain accounts, email addresses, IP addresses, internal paths, tenant identifiers, Keys, or amounts.

Resolution:

Keep only the necessary fields and action context. Use opaque light-gray pixel mosaics for sensitive text and never share complete credentials or internal addresses.

What should I do when the Roles page shows unexpected data? ​

Symptom:

A field, status, metric, or related object differs from the expectation.

Possible causes:

The page scope, time condition, role permission, or upstream setting does not match.

Resolution:

Record the redacted object, time, and result. Verify the entry and filters first, then check related pages and Operation Logs.

Notes ​

  • Authorization changes affect menu visibility and button availability.
  • Before deleting a role, confirm that no critical member depends on it.
  • Confirm is the final submit action. Before adding a role, verify the role name, role code, and later authorization scope.
  • Once Role code is referenced, later changes may affect permission identification, auditing, and automation configuration.
  • For learning or screenshots only, open the dialog to view fields and use Cancel to exit.
  • Do not write real internal role codes, accounts, member IDs, customer names, or internal test data.

Next Steps ​

  1. To view members assigned to roles, go to Members.
  2. To trace permission changes, go to Operation Logs.