Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Create roles and assign permissions
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Create and manage users
Next
Grant access to specific resources →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Access/Create roles and assign permissions

Create roles and assign permissions

A Role is a named bundle of permissions you assign to one or more users, rather than setting access person-by-person. This guide covers creating a role, understanding the two levels of granularity available for each resource type, and reading a role's access at a glance.

Before you begin#

  • Access to Settings → Roles.
  • A sense of which resource types (positions, connections, workflows, and so on) the role actually needs to touch, and at what level.

Create a role#

  1. Open Settings → Roles and select Create Role.
  2. Enter a Name and an optional Description.
  3. Save.
A new role starts with zero permissions: nothing is granted until you add it.

Choose general or granular access#

For each resource type, a role's permissions page offers two cards:
  • All {Resource}s: permissions here apply to every resource of that type, including ones created after this role was set up. Use this when the role should have blanket access to a whole category, such as every connection.
  • Specific {Resource}s: grants access to individual resources only, letting you scope a role down to particular positions, connections, or workflows rather than the whole category.
The two cards don't offer the same ceiling. All {Resource}s offers No access, Read, Update, or Delete, plus separate toggles for Can create new {resource}s and Can execute all {resource}s where those actions apply (the execute toggle requires Read to also be selected). Specific {Resource}s tops out lower: No access, Read, or Update for most resource types, plus an additional Execute column for Workflows and Cuelists. Delete can only be granted through All {Resource}s: there's no way to grant delete access to one specific resource without granting it for every resource of that type.

Read a role's access at a glance#

The Roles list shows each role's granted resource types as icon badges. Hovering a badge summarizes what it actually grants: for example, "Full access to all {resource}s" for complete access, or a narrower summary like "Can read and update some {resource}s" when access is partial or scoped to specific items rather than the whole category.

If you get stuck#

What you see
What to try
A new role doesn't let its users do anything yet.
That's expected: a new role starts with zero permissions. Add the specific resource-type grants it needs.
You're not sure whether a role affects future resources too.
Check whether its permission is set on the All {Resource}s card (applies to new resources automatically) or Specific {Resource}s (scoped to what's explicitly listed, not automatic for new ones).
A user with a role still can't perform an action.
Confirm the role grants at least the right access level (Read/Update/Delete) for that resource type, and, if scoped to specific resources, that the resource in question is actually included.
You want a quick summary of what a role can do.
Hover its resource-type badges on the Roles list rather than opening each permission individually.

Where to go next#

  • Grant access to specific resources, for scoping a role down to individual positions, connections, and other resources.
  • Show different controls by role, for gating what a section shows based on the active role.
  • Create and manage users
  • Understand and manage sessions

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful