Built-in roles
A workspace always has exactly one Creator. Administrators can’t manage billing, change anyone’s role, transfer ownership, or delete the workspace. Those stay with the Creator.
See the permission reference for the full list.
Environment access
Members and Viewers only work in the environments you give them. Creators and Administrators always have every environment.- A new member starts with access to the workspace’s default environment.
- To change it, open Settings → Members, click ⋯ on their row, then Environment access, and tick the environments they should see.
- Everything outside those environments is hidden from them, including projects, variables, and deployments.
Environment access only applies to roles that are limited to assigned environments. If a member’s role covers every environment, Brimble tells you to change the role instead of saving the selection.
Custom roles
Create a custom role when you need a different mix of permissions, for example an Accounting role that manages billing and reads projects, or a Deploy-only role for a contractor. Only the Creator can create, edit, or delete custom roles.Create a custom role
- Open Settings → Members and find Custom roles.
- Click Create role.
- Give it a name and a short description.
- Choose Where can members use this role?:
- Every environment: they can use the role in Production, Staging, and any other environment.
- Only environments you assign: works like Member and Viewer. You pick each person’s environments after assigning the role.
- Pick the permissions the role should allow.
- Review, then click Create role.

Creating a custom role.
What every custom role includes
Every custom role can always:- See the workspace and its members.
- See the workspace’s environments. A role limited to assigned environments only sees the ones you assign.
- Read and dismiss its notifications.
Permissions a custom role can’t have
Four permissions stay with the Creator, because they would let someone take over the workspace:- Delete the workspace (team.delete)
- Transfer ownership (team.transfer_ownership)
- Change members’ roles (team.change_role)
- Create and manage custom roles (role.manage)
Edit or delete a custom role
Changes to a custom role apply to everyone who has it. You can’t delete a role while members still have it; move them to another role first.Permission reference
✓ means the built-in role includes the permission. Custom roles can include any permission except the four listed in Permissions a custom role can’t have.Workspace
Projects and deployments
Environments and variables
Domains and networking
Data, storage, and compute
Observability and integrations
Troubleshooting
“You do not have permission to perform this action in this workspace.” The member’s role doesn’t include the permission that action needs. Check the permission reference, then add the permission to their custom role or give them a role that has it. A member still sees every environment after you limited their access. Their role covers every environment. Edit the role and set Where can members use this role? to Only environments you assign, then pick their environments again. Saving a custom role fails with “Only the workspace creator can hold these permissions”. The role includes one of the four Creator-only permissions. Remove it and save again. You can’t delete a custom role. Members still have it. Move them to another role first.Related
- Manage teams, invite members, change roles, and transfer ownership.
- Create a workspace, set up a new team workspace.