# Custom Collaborator Roles

> Create custom Collaborator roles for Device Management in Applivery and assign them on Segment permissions to give each team exactly the access it needs.

Source: https://docs.applivery.com/en/platform/roles-permissions/custom-collaborator-roles/  •  Last updated: 2026-09-29

**Key topics:** What a Collaborator role is, Roles vs Segment permissions, Workspace and Device Management action groups, How permissions add up across Segments, Creating and assigning custom roles, Applivery, Collaborator, Segment, Device Management

---

**TL;DR:** Create a role with the exact actions a job needs, then assign it on a Segment permission. Workspace actions only apply on the Global Segment.

Custom Collaborator roles let you decide exactly what each [Collaborator](https://docs.applivery.com/en/device-management/getting-started/manage-users/#collaborators) on your team can do in the Device Management area of the Applivery Dashboard. Instead of choosing between **Admin**, **Editor** or **Viewer** for every Segment permission, you can build a role for a specific job, such as helpdesk, store admin or auditor, and reuse it wherever you need it.

That way, nobody gets full Admin access just because they need one extra action in one place.

:::info
This applies to **Device Management** Collaborator roles. [App Distribution Collaborator roles](https://docs.applivery.com/en/app-distribution/distribute/manage-users/#roles-and-permissions) work the same as before.
:::

## What is a Collaborator role

A Collaborator role is a named set of Dashboard actions. It answers **what** a Collaborator can do, but not **where**: that's decided by the Segment permission you assign it to.

Roles live at organization level. You create them once and reuse them across as many Segment permissions as you like. A role doesn't belong to any Segment.

### Built-in roles

**Admin**, **Editor,** and **Viewer** are still available. They're marked as built-in, and you can't edit or delete them. If you want something close to one of them, **Duplicate** it and edit the copy, which becomes a new custom role.

If you open a built-in role without duplicating it, it opens in read-only mode.

### Custom roles

You create custom roles from scratch with **Create role**, or by duplicating an existing role. You can edit their name, description, and actions at any time.

When you pick a role on a permission, the role selector shows the custom role's name. In the **Permissions** and **By collaborators** tables, custom roles show a generic **Custom** tag instead, so long names don't break the layout.

## Roles and Segment permissions

Two layers work together to give someone access:

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><th colspan="1" rowspan="1"><p>Layer</p></th><th colspan="1" rowspan="1"><p>What it decides</p></th><th colspan="1" rowspan="1"><p>Where you manage it</p></th></tr><tr><td colspan="1" rowspan="1"><p><strong>Role</strong></p></td><td colspan="1" rowspan="1"><p>Which Dashboard actions are allowed</p></td><td colspan="1" rowspan="1"><p><strong>Settings</strong> → <strong>Directory</strong> → <strong>Roles</strong></p></td></tr><tr><td colspan="1" rowspan="1"><p><strong>Segment permission</strong></p></td><td colspan="1" rowspan="1"><p>Who gets that role, and on which Segment</p></td><td colspan="1" rowspan="1"><p><strong>Settings</strong> → <strong>Segments &amp; Permission</strong></p></td></tr></tbody></table>

On a Segment permission, you select one role. You can't create or edit the role from the permission itself; instead, the permission shows a read-only preview of the actions included in the selected role.

## Action groups: Workspace and Device Management

Every action belongs to one of two groups:

-   **Workspace** (**W**): organization-level settings and people management, such as Collaborators, Segments, login providers, and the few billing-related actions that aren't Owner-only.
    
-   **Device Management** (**M**): actions on Devices, Policies, enrollment, and other Device Management elements inside a Segment.
    

A role can include Workspace actions, Device Management actions, or both. The **Roles** list and the role selector show a **W** and an **M** badge for each role: the badge is highlighted when the role has actions in that group, and greyed out when it has none.

**Owner-only actions**, such as transferring ownership, deleting the workspace, and most billing management actions, are shown in the Workspace group but stay locked. They can't be granted through any role.

![built in roles](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/863777de-c3b5-4403-af49-4af91fed2572.png)

### Workspace actions only apply on Global

Workspace actions only take effect when the Segment permission sits on **Global**, the root Segment of your tree.

If you assign a role that includes Workspace actions on a child Segment:

-   The role's Device Management actions still apply on that Segment.
    
-   Its Workspace actions don't take effect there.
    
-   The Dashboard shows a warning under the **Role** field, but you can still save.
    
-   The read-only preview hides the Workspace section, since those actions won't apply.
    

![segment perms](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/c62410a2-674f-427c-a4d6-5c53a7f2c996.png)

## How permissions add up across Segments

Permissions **add up** as you go down the [Segment](https://docs.applivery.com/en/device-management/general-settings/segments/) tree. Here's an example:

-   A Collaborator has **Viewer** on **Global**.
    
-   The same Collaborator has a custom role with extra Device Management actions on **Madrid**, a child Segment.
    

On Madrid, that Collaborator can do everything Global and Madrid grant combined.

This also means a permission on a child Segment **can't remove** actions granted higher up in the tree. If someone needs fewer actions in one store than in the whole region, assign the narrower role at the store level (or lower), rather than a wide role at the region level.

:::info
The permission preview only shows the actions in the selected role. It doesn't include what the Collaborator already has from permissions on parent Segments.
:::

## How to create a Collaborator role

**Go to Roles**

Once in the [**Applivery Dashboard**](https://dashboard.applivery.io/), navigate to the **Settings** section 1 and, in the left-hand menu under **Directory**, select **Roles** 2.

**Create the role**

Click **Create role** 3, then enter a name and a description for it.

![create role](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/60e212f9-e127-4a35-9cd5-1fee51090065.png)

**Select the actions**

If you want to start from an existing role's actions, choose it as a template 4. Then select or clear the actions you need in the **Workspace** and **Device Management** groups 5. Owner-only actions stay locked.

![role modal](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/c6d97939-11b8-4cfe-9ab2-4d3f66cc1b9c.png)

**Save**

Save the role. It's now available to assign on any Segment permission.

To create a custom role based on a built-in one, open **Admin**, **Editor,** or **Viewer**, click **Duplicate,** and edit the new role.

## How to assign a role on a Segment permission

This follows the same flow you use to [create Segments and permissions](https://docs.applivery.com/en/device-management/general-settings/segments/#how-to-create-segments-and-permissions), with the new role options.

**Open the Segment**

Once in the [**Applivery Dashboard**](https://dashboard.applivery.io/), navigate to the **Settings** section 1, select **Segments & Permission** 2 from the left-hand menu, select the Segment 3, and create or edit a permission 4.

![role and segment](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/eb1dbbd7-30d0-4cc0-b52e-b3a9f06e9814.png)

**Name the permission and choose the role**

Give the permission a clear name and choose the role, either built-in or custom. Check its **W** and **M** badges to see which groups of actions it includes.

If the Segment isn't Global and the role includes Workspace actions, you'll see a warning. Remember that those Workspace actions won't apply to this Segment.

**Add who gets it**

Add the groups and/or email addresses that match this permission.

**Review and save**

Check the read-only preview of the role's actions and save.

You can't change individual actions on a single permission. To adjust them, edit the role, or create a new one and assign it instead.

## Things to keep in mind

-   **App Distribution** Collaborator roles aren't affected by custom roles. See [Manage users in App Distribution](https://docs.applivery.com/en/app-distribution/distribute/manage-users/#roles-and-permissions).
    
-   **Inventory** actions aren't part of custom roles.
    
-   A permission on a child Segment can't deny or remove actions granted on a parent Segment.
    
-   Each permission uses one role as it is. There's no way to customize actions per permission without creating or editing a role.
    
-   Custom roles are for people. Service accounts used for API access and automation have their own roles. See [Service Accounts](https://docs.applivery.com/en/platform/api/service-accounts/).
