NearSync Help

Settings

Permissions How to change what a role can do safely: stage the change, preview who it affects, then commit.

Settings, Access, Permissions. This is where you change an existing role's capabilities. It is built so you cannot make a change without seeing its consequences first. You need weight 60 or above, plus the capability to manage roles.

The Mental Model

Every role reads as one sentence:

This role can [capabilities], on records inside [hub scope], for people they are connected to.

Three separate things. This surface sets the first. Hub scope is set here too, on the "works in" control. Participation - whether they see only records they own, are assigned to, or watch - follows from the record itself.

The Safe Edit Loop

Changes do not apply as you click. They stage.

  1. Select the role you want to change.
  2. Tick and untick capabilities. Each change is added to a staged changeset. Nothing has happened yet.
  3. Review. You are shown a diff: exactly which capabilities are gained, which are lost, and how many people are affected.
  4. Commit. The whole changeset applies at once.

Because it commits atomically, you never end up with half a change applied. If it fails, nothing changed.

Tip

The "people affected" number is the one to read. Changing a role held by one person is a small decision. Changing one held by forty is a different kind of decision, and the number is the only thing that tells you which you are making.

Reading The Grid

Capabilities are grouped by area, and inside each area by the See, Do, Manage and Admin rungs described in Roles.

Two glyphs mark capabilities that deserve a second look:

  • Money - the capability touches financial data.
  • Personal data - the capability touches personal information.

Removing a sensitive capability prompts a soft confirmation before it is staged, and the final check happens at review.

You Cannot Lock Yourself Out

Two capabilities are treated as gate keys: managing roles, and managing settings. Removing either from your own role is disabled in the interface, and refused by the server if attempted another way.

This is why you may find a checkbox you cannot untick. It is not a bug - it is the one that would remove your ability to undo the change.

Caution

The protection covers your own role only. You can absolutely remove the last other person's ability to manage roles. Before committing a change to an admin role, check the affected-people count and confirm at least one other person keeps the gate keys.

Owner-Level Roles

A role at weight 90 or above bypasses individual capabilities at runtime. The surface says so plainly and marks the editors cosmetic for that role - ticking boxes changes nothing, because the role can already do everything.

To genuinely limit someone, lower the weight below 90 and grant capabilities explicitly.

Presets

You can stage a role to match a template rather than ticking by hand. Choosing a preset shows the same diff - how many capabilities would change, how many people are affected - which you then review and apply, or discard.

Works In: Hub Reach

On multi-hub workspaces there is a second control alongside the capability grid: which hubs this role operates in.

  • Leave it global and the role works across every hub.
  • Restrict it and you pick the specific hubs it covers.

Saving a reach change previews the number of people affected and asks you to confirm before it applies.

Reach is a property of the role. It is coarse. For one person who needs an exception - a manager covering a second office for a quarter - use a per-person grant instead. See Who Sees Whose Records.

A Worked Change

Giving the sales team the ability to send contracts, without giving them the ability to delete deals.

  1. Select the Sales Representative role.
  2. Search for contract capabilities and tick the send capability under Do.
  3. Check that nothing under Admin got ticked - deletion lives there.
  4. Review. Confirm the diff shows one capability gained and nothing lost, and note how many people are affected.
  5. Commit.
  6. Verify by asking one of them to open a deal and send a contract.

Common Questions

I ticked boxes and left the page. Are they applied? No. Staged changes are not committed changes. You have to review and commit.

The diff shows a capability lost that I did not untick. Check whether you applied a preset. Staging to match a template both adds and removes.

Why can I not untick this one? It is a gate key on your own role. Removing it would lock you out of this surface.

Where do I create a new role? On the Roles surface. This one edits existing roles. See Roles.

9 minUpdated 28 July 2026

Did this answer your question?

No, ask a person