Skip to content

Roles & permissions

Roles are reusable permission sets for your organisation. Each user has one role, and each permission is either enabled or disabled.

The Roles page is available to the Customer Super Admin and users with Add Roles permission.

System roles

RebelCore includes three system roles:

RoleIntended use
RebelCore_SuperUserBroad portal and Agent access for trusted administrators and operators.
RebelCore_UserDay-to-day project, dataset, Tree, and Agent access.
RebelCore_AgentUserAgent-only access with no customer portal navigation.

System roles are marked System and cannot be edited or deleted. Create a custom role when you need a different combination of permissions.

The Customer Super Admin is the organisation owner and is not controlled by these roles. The owner retains access to all customer administration features.

Permission reference

PermissionWhat it allows
View DatasetsOpen the Datasets page and view available datasets.
Add DatasetsStart an import and upload source files.
Add ModuleCurate an uploaded dataset and build its module.
Add ProjectsCreate and edit projects.
View TreeOpen projects and navigate the Tree.
Create Semantic DatasetBuild a semantic dataset from a Tree selection.
Delete Semantic DatasetPermanently delete a semantic dataset.
Access AgentOpen and use RebelCore Agent.
Add UsersInvite, edit, deactivate, and remove customer users.
Add RolesCreate, edit, and delete custom roles.

Some permissions have prerequisites:

  • Add Datasets requires View Datasets.
  • Add Module requires both View Datasets and Add Datasets.

The role editor selects required prerequisites automatically and prevents combinations that would leave an action inaccessible.

Create a custom role

  1. Open Roles under Accountability.
  2. Click the + button.
  3. Enter a clear role name and description.
  4. Enable only the permissions the role requires.
  5. Click Create.

Use names based on responsibilities, such as Data Steward, Project Analyst, or Read-only Agent User.

Edit a role

Select a custom role, change its permissions, and save. Users assigned to that role receive the updated access the next time RebelCore refreshes or they make a new request.

Delete a role

System roles cannot be deleted.

For an unused custom role:

  1. Select Delete.
  2. Type yes when prompted.
  3. Confirm the deletion.

If users are assigned to the role, first choose an active replacement role in Move users to. RebelCore reassigns those users before removing the old role.

Account types outside custom roles

Some access is determined by account responsibility rather than an editable role:

  • Customer Super Admin can administer the customer and open Audit, Activity, and Customer Settings.
  • Data Protection Officer and Security Officer can access the governance areas assigned to their responsibilities.
  • CAS users use the separate platform-administration application.

Customer accounts are scoped to one organisation. Cross-customer access is not provided through roles.

  • Start with the least access required.
  • Separate data import, project curation, Agent use, and administration where practical.
  • Use a dedicated Agent-only role for people who do not need the portal.
  • Review custom roles when responsibilities change.
  • Use Activity to review role and user administration.