Custom Roles: create a role with exactly the permissions each job needs
Account Admins can build up to 20 roles, each with its own record access, settings, reporting and AI permissions — with ready-made setups for setters, closers, team leads, canvassers and billing contacts.
Applies to: Roles are created and edited on web. Permissions are enforced on web, mobile and the API. Audience: Account Admins Plan: All accounts
What custom roles are
Until now, an account's roles came from a fixed set: Sales Rep, Manager, and Account Admin. We know that often times, teams don't always divide just that way. Setters and closers do different jobs. A team lead is part rep, part manager. A canvasser shouldn't be reading the last rep's notes. A CFO needs billing and nothing else.
Custom Roles lets an Account Admin build a role for each of those jobs, granting exactly the permissions that job requires — no more, no less. An account can hold up to 20 roles,
Permissions are now configured in a single place, described in plain language, and applied the same way whether the user is on web, on mobile, or coming through the API. Roles themselves are created and edited on web.
Turning it on changes nothing on day one. When Custom Roles is enabled, your existing roles are mapped into the new structure with the exact permissions they already had. Nobody's access changes until you change it.
Where to find it
Role permissions have moved out of Settings → General → Permissions & Security into their own top-level Permissions tab in Settings.
Account-level security settings stay under General. Everything role-related is now in Permissions.
Only Account Admins can open the Permissions tab. This is not a permission you can grant. No role — custom or system — can ever be given the ability to create, edit, clone, or delete roles. The User Management permission covers managing users, not roles.
The role list
The Permissions tab opens on a list of every role on your account:
| Column | What it shows |
|---|---|
| Name | The role name |
| Description | What the role is for (worth filling in — it appears again when you assign users) |
| Type | System or Custom |
| Users | How many users are on the role. Click the blue number to jump into Users & Teams filtered to that role. |
| Last modified | When the role was last changed |
Two icons sit on each row:
- Clone (clipboard icon) — copies every permission from that role into a new draft titled "Copy of [Role]," carrying the original description across with it. Rename both, change what needs changing, save. This is the fastest way to build a role.
- Edit (pencil icon) — opens the role editor.
System roles vs. custom roles
Three system roles ship with every account and can't be deleted. What you can change differs by role:
| Role | Delete | Rename / edit description | Edit permissions |
|---|---|---|---|
| Account Admin | No | No | No — permanently has full access to everything |
| Sales Rep | No | Yes | Yes |
| Manager | No | Yes | Yes |
| Any custom role | Yes | Yes | Yes — fully configurable |
Account Admin cannot be renamed, edited, or restricted at all.
Building a role
Click Create New Role to open the role editor.
Every role starts with Role Details: a name (required, up to 50 characters) and an optional description.
Below that, permissions are organized into six tabs: Records & Activities, Access Management, Account Settings, AI Capabilities, Reporting, and Other. Every permission carries a one-line plain-language description of exactly what it controls, so you can read the editor rather than guess.
Every setting in all six tabs is documented below, under Permission reference.
Rolling out a new role structure
The fastest path is clone, then bulk-move.
- Clone the closest existing role. Most accounts shouldn't build from scratch. Clone Sales Rep (or Manager, or another custom role), rename the copy, and adjust only the handful of permissions that differ.
- Save the role.
- Bulk-move users onto it. From the role list, click the blue user count on the role people are on today to jump into Users & Teams filtered to that role. Select users with the checkboxes on the left, then use the Change Role bulk action to reassign all of them in one operation.
Between cloning and the bulk role change, standing up a full role structure and staffing it is a few minutes of work rather than a long session of one-by-one edits.
Permission reference
Use your browser's find (Ctrl+F / ⌘+F) to jump to a setting by name.
Records & Activities
This is the heart of the role — what the person can actually see and touch.
Record Level Visibility
A toggle at the top of the tab controls how granular you get:
- Off — one Record Types tab. Set the permissions once and they apply to every record type.
- On — a sub-tab appears for each record type on your account (Lead, Company, Contact, and so on), and every record and activity permission on this tab is set independently per type.
Turn it on when a role should work one record type and not others — for example, a setter role with full Lead access and no access to Companies at all.
If your account uses Object Level Visibility today, Record Level Visibility is where that capability now lives — built into each role rather than configured separately.
Record access
View, Create, Update, and Delete are each set independently to one of five scopes:
| Scope | What the user can reach |
|---|---|
| Assigned to user | Only records they own. |
| Assigned to user + Ghost records | Their own records, plus ghost pins for other records in their team or territory. A ghost pin shows that a record exists at an address, with all details hidden. |
| Within assigned teams/territories | Everything inside the team or territory they're assigned to. |
| Within assigned teams/territories + Ghost records | Everything inside their assignment, plus ghost pins for records outside it. |
| All records | Everything on the account — the traditional admin posture. |
Teams or territories? Whether your account runs team-based or territory-based visibility is an account-level setting managed by SPOTIO Support — it hasn't changed with this release. The editor automatically reads "teams" or "territories" to match your account. Hover the info icon next to Access to see which model you're on.
Activity access
Activity permissions sit below record access and work the same way, with one difference: ownership here is at the activity level, not the record level.
Scheduled activities get View, Create, Update, and Delete, each scoped to:
- Own + on records assigned to user
- Own + on records assigned to user + Ghost records (a ghost activity shows a time slot is taken without revealing what it is)
- Own + on records within assigned teams/territories
- On all visible records
Completed activities are controlled separately, with a View permission scoped to:
- Own + on records assigned to user
- Own + on records within assigned teams/territories
- On all visible records
Splitting these lets you do things like show a role every upcoming appointment while hiding historical outcomes. With Record Level Visibility on, all of it is set per record type.
Reset Activity Visibility on Reassignment
A per-role, per-record-type toggle in the Completed section.
When it's on, users on this role only see activity history created while the record was assigned to them. When a record is reassigned, the new owner starts with a clean slate — no prior visits, results, or notes.
This is built for door-to-door teams that want every knock approached fresh, without the previous rep's "not interested" coloring the next conversation. When it's off, reassignment does nothing special and the role's normal view settings apply.
Default Types
Each role can set a Default Record Type (pre-selected when tapping the map or creating a record) and a Default Activity Type (pre-selected when logging or scheduling).
These are defaults, not restrictions — users can still pick any type their permissions allow. The role's Default Record Type overrides the general workflow setting.
Export
Two independent toggles: Record Export and Activity Export. Activity exports include the associated record information where available.
When a toggle is off, the export button doesn't appear for that role at all. Restricting export is common on rep-level roles, so that account data can't be carried out in a spreadsheet.
Advanced Options
These capabilities were previously fixed to the Manager or Admin roles. Any role can now be granted them:
| Option | What it does |
|---|---|
| Record Merging | Combine duplicate records into one, choosing which field values to keep. |
| Read-only field editing | Edit fields that are otherwise read-only. Previously Admin-only. |
| Custom filters (My Filters) | Four levels — Use Existing (use filters shared with you), Manage Own (create filters only you see), Manage Own & Share, and Manage All & Share (the admin tier). |
Access Management
Managing users, teams, and territories was previously an Admin responsibility, with a small number of scopes configurable on Manager and nothing available to reps. That left hybrid jobs — a team lead who still sells but also runs three people — without a role that fit. Any role can now be granted any part of it.
User Management — a single toggle. On, the role can add, edit, and suspend users, and the Users & Teams tab appears in their Settings. Off, it's hidden entirely.
This grants user management only. It never includes creating or editing roles — that stays Account Admin only.
Teams and Territories — parallel sections, each with View, Create, Update, Delete, and Assign, independently scoped to:
| Scope | What it means |
|---|---|
| None | No access to this action. |
| Within assigned teams/territories | Act only inside the parent team or territory the user belongs to. Someone assigned to a Texas territory can build and manage sub-territories inside it, and reach nothing beyond it. |
| Any | Account-wide. |
Labels flip between "teams" and "territories" to match your account's visibility model.
Account Settings
The web Settings navigation was previously visible in full only to Account Admins. A handful of pages could be opened up to Managers, reps saw none of it, and none of that was adjustable.
Each Settings page now has its own per-role toggle:
General Configuration · Workflow Management · SPOTIO Numbers · E-Contracts · Data Import · System Logs · Integrations · Links · Billing
- All toggles off — the role has no Settings entry point at all. This matches the traditional Sales Rep experience, and is where most field roles should sit.
- All toggles on — the role sees the full Settings navigation, like a traditional Admin.
Two Settings areas deliberately live elsewhere: Users & Teams is governed by the User Management toggle on Access Management, and AI Chat is governed from AI Capabilities. The Permissions tab is never in this list.
These settings are account-global. Anyone granted a page can change things that affect every user on the account. Per-page control is what makes narrow delegation safe: a finance contact can be given Billing on its own, with no route into anything else.
AI Capabilities
Per-role control of the DASH suite.
This tab only shows toggles for AI features your account is actually provisioned for. A role can never grant a feature the account doesn't have.
| Permission | What it controls |
|---|---|
| AI Chat | Access to DASH conversational AI for asking questions about records, pipelines, and activity. |
| ↳ Perform Actions | Lets DASH act on the user's behalf — adding notes, updating records, queuing follow-ups. Requires AI Chat. Grant chat only, or chat + actions. |
| Next Best Action | On/off for the Next Best Action feature suite, on accounts that have it. |
| Enable MCP Access | Whether the role can connect SPOTIO data to compatible external clients through the SPOTIO MCP connector (set up under profile settings on web). |
| AI Chat Guidelines | Access to the AI Chat settings tab, where DASH's behavior and account-wide AI guidance are configured. |
Reporting
Reporting has been part of SPOTIO for years, but which reports a role could reach was fixed. It is now configurable.
| Permission | What it controls |
|---|---|
| Rep Overview | The rep overview section on the Home screen, where management-type users see a day-level view of their reps. |
| Account Overview | The Account Overview section under Dashboard → Reports — high-level account-wide performance and activity metrics. |
| In-depth Metrics | The detailed reports under Dashboard → Reports (activities, activity feed, and so on). |
Rep Overview and In-depth Metrics don't widen what someone can see — results stay scoped to the users and records the role already has access to. Account Overview is account-wide by design, so grant it only to roles that should see whole-account numbers.
If both Account Overview and In-depth Metrics are off, the Dashboard tab disappears for the role entirely.
My Reports has its own sidebar icon
A role can now have every Dashboard toggle off and still see and manage My Reports through its own entry in the left sidebar — so reps get their own reports without the full Dashboard.
Custom Reports (My Reports) has three levels:
- Manage Own — build and edit reports only you see
- Manage All & Share Restricted — manage all My Reports and share within your visibility or hierarchy
- Manage All & Share Publicly — manage all and share org-wide (the admin tier)
Other
| Permission | Levels |
|---|---|
| Company Documentation | Browse & Download (view and download company documents, including content DASH can be trained on), with Upload, Modify & Delete nested beneath it for write access. Leave both off for no documentation access. |
| Lead Machine | Filter Database & Download Leads — access to the web-only Lead Machine workflow: draw an area on the map, filter it by criteria, and add the results as records in bulk. Previously manager/admin only. |
| Routing | Manage Own (your own routes) or Manage All & Share (manage common and saved routes created by others, and share routes to all users). |
| Communication Templates | Pre-written texts and emails reps can send. Use Existing, Manage Own & Share, or Manage All & Share. |
| Autoplays | Use Existing, Manage Own, or Manage All & Share. |
| Edit Own Profile Information | On by default — users can edit their own name, email, phone, and photo. Turn it off to reserve profile and credential changes for admins. |
| Disable Own Location Sharing | Whether the user can turn off their own location sharing from profile settings. Previously Admin-only; other roles could only scope tracking to working hours. |
Bulk Actions
Seven independent toggles, so you can delegate the safe ones and hold back the risky ones:
Bulk Send Texts and Emails · Bulk Schedule Tasks · Bulk Reassign Records · Bulk Change Stage · Bulk Delete Records · Bulk Add Records to Routes · Bulk Enroll Records in Autoplays
A common setup: leave bulk communications on for reps, and keep Bulk Change Stage off so pipeline tracking stays intact.
Frequently asked questions
Will turning this on change anyone's access? No. Your existing roles are mapped into the new structure with exactly the permissions and settings they had before. Nothing changes for any user until an admin changes it.
How many roles can I have? Up to 20 per account, counting the roles your account already has.
Can I give a manager the ability to create roles? No. Role creation and permission management is Account Admin only, and it is not a grantable permission. The User Management permission lets someone manage users, not roles.
Can I delete Sales Rep or Manager? No. The three system roles can't be deleted. You can rename Sales Rep and Manager, edit their descriptions, and change their permissions. Account Admin is fully locked.
Can I move a lot of users to a new role at once? Yes. Click the blue user count on any role in the Permissions tab to open Users & Teams filtered to that role, select the users, and use the Change Role bulk action.
Do role permissions apply on mobile? Yes. Roles are enforced identically on web, mobile, and the API.
What's a ghost record? A pin that shows a record exists at an address, with every detail hidden. It tells a rep that turf is already worked without exposing whose record it is or what happened there. Ghost activities work the same way for time slots.
Does my account use teams or territories? That's an account-level setting managed by SPOTIO Support and it hasn't changed. Hover the info icon next to Access in the role editor to see which model you're on.
A user can't see a feature I think I granted. Where do I look first? Check the role they're actually assigned to, then check whether the feature has a dependency. Two common ones: Perform Actions requires AI Chat, and the AI Capabilities tab only shows features your account is provisioned for.
Glossary
- System role — Account Admin, Sales Rep, or Manager. Ships with every account and can't be deleted.
- Custom role — a role an Account Admin creates. Fully configurable and deletable.
- Clone — copying every permission from an existing role into a new draft.
- Scope — how far a permission reaches: the user's own records, their team or territory, or the whole account.
- Ghost record — a pin showing that a record exists at an address, with all details hidden.
- Ghost activity — an entry showing a time slot is occupied, without revealing what it is.
- Record Level Visibility — the toggle that sets record and activity permissions separately per record type.
- Reset Activity Visibility on Reassignment — the setting that gives a new record owner a clean activity history.