> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plato.ae/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles

> Create roles and decide which Console pages, apps, and actions teammates can use.

Roles define what each teammate can see and do inside Plato. They help you give people enough access to do their work without giving everyone full control of the workspace.

<img src="https://mintcdn.com/platoae/NRPvZwQQD0AeWQue/images/console/root/roles-tap.png?fit=max&auto=format&n=NRPvZwQQD0AeWQue&q=85&s=0e002e68869e272ce2e35a68f3375bff" alt="Roles page" width="1280" height="720" data-path="images/console/root/roles-tap.png" />

## When To Create A Role

Create a role when a group of people needs the same access. For example:

* A manager who needs to review daily operations.
* A staff member who should only use one app.
* A finance teammate who needs billing or reports.
* A connected tool that should only use API access.

## Create A Role

1. Open `Roles & Permissions`.
2. Click `New Role`.
3. Enter the role name.
4. Add a description.
5. Choose a status.
6. Choose what the role can access.
7. Click `Save`.

<img src="https://mintcdn.com/platoae/NRPvZwQQD0AeWQue/images/console/root/roles-new-role-modal.png?fit=max&auto=format&n=NRPvZwQQD0AeWQue&q=85&s=e120d78e6b9c30ca8c7aade5201fbe27" alt="Create role drawer" width="1440" height="810" data-path="images/console/root/roles-new-role-modal.png" />

## Choose Access

Each section gives you three choices:

* `Full` allows everything in that section.
* `Some` lets you choose only specific actions.
* `None` blocks access to that section.

Use `Some` when a teammate only needs part of a section. For example, a staff member might need to read orders but not change workspace settings.

<img src="https://mintcdn.com/platoae/NRPvZwQQD0AeWQue/images/console/root/roles-new-role-access.png?fit=max&auto=format&n=NRPvZwQQD0AeWQue&q=85&s=675e7695764278fc69daaa7a196c0c3a" alt="Scrolled role access options" width="1440" height="810" data-path="images/console/root/roles-new-role-access.png" />

## Common Role Examples

Workspace owner: full access to apps, members, roles, configuration, domains, and API keys.

Manager: access to the apps and daily actions they manage, with limited access to sensitive settings.

Staff: access only to the app and actions they need for their work.

Connected tool: access only to the apps and actions the tool needs.

## Keep Roles Clean

Review roles when someone changes jobs, leaves the business, or no longer needs the same access.

Avoid giving full access unless the person truly needs to manage the workspace.
