Skip to main content
Every member of a workspace has a role. The role decides which actions they can take, and whether they can work in every environment or only the ones you assign to them. Brimble has four built-in roles, and you can create custom roles when none of them fit.

Built-in roles

A workspace always has exactly one Creator. Administrators can’t manage billing, change anyone’s role, transfer ownership, or delete the workspace. Those stay with the Creator. See the permission reference for the full list.

Environment access

Members and Viewers only work in the environments you give them. Creators and Administrators always have every environment.
  • A new member starts with access to the workspace’s default environment.
  • To change it, open Settings → Members, click ⋯ on their row, then Environment access, and tick the environments they should see.
  • Everything outside those environments is hidden from them, including projects, variables, and deployments.
Environment access limits where someone can act, not what they can do. A Viewer with access to Production still can’t deploy there.
Environment access only applies to roles that are limited to assigned environments. If a member’s role covers every environment, Brimble tells you to change the role instead of saving the selection.

Custom roles

Create a custom role when you need a different mix of permissions, for example an Accounting role that manages billing and reads projects, or a Deploy-only role for a contractor. Only the Creator can create, edit, or delete custom roles.

Create a custom role

  1. Open Settings → Members and find Custom roles.
  2. Click Create role.
  3. Give it a name and a short description.
  4. Choose Where can members use this role?:
    • Every environment: they can use the role in Production, Staging, and any other environment.
    • Only environments you assign: works like Member and Viewer. You pick each person’s environments after assigning the role.
  5. Pick the permissions the role should allow.
  6. Review, then click Create role.
Walkthrough of creating a custom role in workspace settings

Creating a custom role.

To give someone the role, change their role on the member’s row and pick it from the list.

What every custom role includes

Every custom role can always:
  • See the workspace and its members.
  • See the workspace’s environments. A role limited to assigned environments only sees the ones you assign.
  • Read and dismiss its notifications.
A custom role that can create, change, or delete something can also view it. For example, a role that can update domains can also see domains, even if you didn’t tick domain.read.

Permissions a custom role can’t have

Four permissions stay with the Creator, because they would let someone take over the workspace:
  • Delete the workspace (team.delete)
  • Transfer ownership (team.transfer_ownership)
  • Change members’ roles (team.change_role)
  • Create and manage custom roles (role.manage)
Brimble rejects a custom role that includes any of them. Billing (billing.manage) is allowed, so you can give a finance or accounting role access to billing without making them the Creator.

Edit or delete a custom role

Changes to a custom role apply to everyone who has it. You can’t delete a role while members still have it; move them to another role first.

Permission reference

✓ means the built-in role includes the permission. Custom roles can include any permission except the four listed in Permissions a custom role can’t have.

Workspace

Projects and deployments

Environments and variables

Domains and networking

Data, storage, and compute

Observability and integrations

Troubleshooting

“You do not have permission to perform this action in this workspace.” The member’s role doesn’t include the permission that action needs. Check the permission reference, then add the permission to their custom role or give them a role that has it. A member still sees every environment after you limited their access. Their role covers every environment. Edit the role and set Where can members use this role? to Only environments you assign, then pick their environments again. Saving a custom role fails with “Only the workspace creator can hold these permissions”. The role includes one of the four Creator-only permissions. Remove it and save again. You can’t delete a custom role. Members still have it. Move them to another role first.
Last modified on September 28, 2026