Skip to main content

Team Roles and Permissions

Roles and permissions allow team owners to control who can access specific resources and perform particular actions within a Frappe Cloud team. They help improve security by granting members only the permissions they need.

Why Use Roles and Permissions?

As organizations grow, managing access for every team member becomes more important. While the team owner retains complete control over team-level operations, other members may only need access to specific resources or administrative tasks.

For example, a team member may need permission to:

  • Manage a particular site.
  • Update a bench or server.
  • Access only a single resource without viewing the rest of the team’s infrastructure.

Roles and permissions are designed to restrict access rather than simplify it. They act as security boundaries that help protect your team’s resources.

Understanding Roles

Using Frappe Cloud Without Roles

If your team does not use roles, every team member automatically has unrestricted access to all resources within the team.

This setup is common for small teams where every member is trusted with full administrative access.

No Roles Configured

When no roles exist, permission restrictions are disabled and all team members have full access to team resources.

When Roles Are Enabled

Creating your first role enables the permission system.

From that point onward, access is controlled through explicit permission assignments.

This means:

  • Access is denied by default.
  • Users can access only the resources included in their assigned roles.
  • Permissions must be explicitly granted.

For example, if a member needs access to foobar.frappe.cloud, they must belong to a role that explicitly includes that site.

Important

Once roles are enabled, members cannot access resources unless those resources are explicitly assigned to one of their roles.

Creating and Managing Roles

You can manage roles from the Team Settings page.

From there, you can:

  • Create new roles.
  • Add team members to a role.
  • Assign resources to the role.

Viewing Role Details

Selecting an individual role opens a detailed view where you can manage:

  • Assigned members.
  • Accessible resources.
  • Permission settings.

This makes it easy to review which users can access specific sites, benches, servers, or other resources.

Role Permissions

Each role can be customized by enabling or disabling individual permissions.

Permissions determine what actions members assigned to the role are allowed to perform on the resources available to them.

By carefully configuring permissions, you can ensure that users have only the access required for their responsibilities.

Beta Feature

Roles and permissions are currently in Beta. You may encounter occasional issues or incomplete functionality. If you experience any problems, please report them to the Frappe Cloud team so they can be addressed.

Rating: 0 / 5 (0 votes)