Roles & permissions
Roles are reusable permission sets for your organisation. Each user has one role, and each permission is either enabled or disabled.
The Roles page is available to the Customer Super Admin and users with Add Roles permission.
System roles
RebelCore includes three system roles:
| Role | Intended use |
|---|---|
| RebelCore_SuperUser | Broad portal and Agent access for trusted administrators and operators. |
| RebelCore_User | Day-to-day project, dataset, Tree, and Agent access. |
| RebelCore_AgentUser | Agent-only access with no customer portal navigation. |
System roles are marked System and cannot be edited or deleted. Create a custom role when you need a different combination of permissions.
The Customer Super Admin is the organisation owner and is not controlled by these roles. The owner retains access to all customer administration features.
Permission reference
| Permission | What it allows |
|---|---|
| View Datasets | Open the Datasets page and view available datasets. |
| Add Datasets | Start an import and upload source files. |
| Add Module | Curate an uploaded dataset and build its module. |
| Add Projects | Create and edit projects. |
| View Tree | Open projects and navigate the Tree. |
| Create Semantic Dataset | Build a semantic dataset from a Tree selection. |
| Delete Semantic Dataset | Permanently delete a semantic dataset. |
| Access Agent | Open and use RebelCore Agent. |
| Add Users | Invite, edit, deactivate, and remove customer users. |
| Add Roles | Create, edit, and delete custom roles. |
Some permissions have prerequisites:
- Add Datasets requires View Datasets.
- Add Module requires both View Datasets and Add Datasets.
The role editor selects required prerequisites automatically and prevents combinations that would leave an action inaccessible.
Create a custom role
- Open Roles under Accountability.
- Click the + button.
- Enter a clear role name and description.
- Enable only the permissions the role requires.
- Click Create.
Use names based on responsibilities, such as Data Steward, Project Analyst, or Read-only Agent User.
Edit a role
Select a custom role, change its permissions, and save. Users assigned to that role receive the updated access the next time RebelCore refreshes or they make a new request.
Delete a role
System roles cannot be deleted.
For an unused custom role:
- Select Delete.
- Type
yeswhen prompted. - Confirm the deletion.
If users are assigned to the role, first choose an active replacement role in Move users to. RebelCore reassigns those users before removing the old role.
Account types outside custom roles
Some access is determined by account responsibility rather than an editable role:
- Customer Super Admin can administer the customer and open Audit, Activity, and Customer Settings.
- Data Protection Officer and Security Officer can access the governance areas assigned to their responsibilities.
- CAS users use the separate platform-administration application.
Customer accounts are scoped to one organisation. Cross-customer access is not provided through roles.
Recommended practice
- Start with the least access required.
- Separate data import, project curation, Agent use, and administration where practical.
- Use a dedicated Agent-only role for people who do not need the portal.
- Review custom roles when responsibilities change.
- Use Activity to review role and user administration.