Assign roles to groups
Assign organization roles and object roles to permission groups in Retool.
Assign organization roles and object roles to groups from the Settings > Groups page.
Organization roles
- Navigate to Settings > Groups and select a group.
- Go to the Organization permissions tab.
- Click Add role.
- Select the organization roles to assign.
- Click Save.
To remove an organization role, click the Delete icon next to the role on the Organization permissions tab.
Default roles cannot be removed from their associated default groups.
Object roles
Object roles are assigned from the Groups page, on the Object Permissions tab. The View by toggle (Object or Role) only changes how existing permissions are displayed.
Each object type in an object role has a grant type, either Universal or Individual. The grant type is set with the Apply universally toggle when the role is created.
- Universal grants cover every object of that type in the organization, including objects created later.
- Individual grants cover only the objects or folders you select. You choose them each time you assign the role, so the same role can be scoped to different objects for different groups.
To grant a group access to specific objects when the role's grant type is universal, create a separate role with Apply universally turned off. Refer to Grant types for more information.
From the Object view
- Navigate to Settings > Groups and select a group.
- Go to the Object Permissions tab.
- Set View by to Object.
- Click Add object.
- Select an object role.
- For individual access, select the specific objects or folders to scope the role to.
- Click Save.
From the Role view
- Navigate to Settings > Groups and select a group.
- Go to the Object Permissions tab.
- Set View by to Role.
- Click Add role.
- Select an object role.
- For individual access, select the specific objects or folders to scope the role to.
- Click Save.
When you scope a role to a folder, the permission applies to all objects within that folder, including objects added later. If an object is moved to a different folder, it inherits the permissions of its new parent folder.