Skip to main content

Designing Smarter Custom Roles: Real Questions, Real Answers (08/11/2026)

Originally recorded August 11, 2026

Summary

With Kadince's enhanced roles and permissions live for over a month, this webinar tackled the most common questions we'd been hearing. We covered when to use standard vs. custom permissions (and why that choice is a one-way street), how to build a new role instead of editing an existing one, and how to scope access so every user sees exactly what they need.

We walked through real examples and shared the pitfalls to avoid, giving teams a clear path to firm up permissions that still felt like a work in progress.


Downloadable Take-Home Resource



Key Takeaways

  • Standard → custom is a one-way door. Once a role is converted to custom it can't be reverted. Clone the role first, convert the clone, and test before moving any users over.

  • Forms now drive the ability to submit — and to be an owner. The old submit checkbox is gone. If a role has no form assigned for an object, that user can't create or clone records in it and won't appear as an available owner. This was the #1 source of post-migration "where did my people go?" questions.

  • Roles are per-module, not global. Community, feedback, and marketing each need their own role. "View any task" on a community role only covers community objects — mirror the permission on every module where the user needs it.

  • Permissions are only step one; detail views are step two. Permissions decide whether a user gets in the record; the detail view controls which fields they see and can edit. Cloning custom detail views per user group is often the better fix than stripping edit permission entirely — and poor detail views are the top non-admin complaint in NPS feedback.

  • In custom roles, conditions work like report filters. No object listed = no permission at all. Object listed with no conditions = access to everything in it. Add condition groups (e.g., approval status doesn't include approved, owner is current user) when you need status- or ownership-based control — that's the only way to get "view everything, edit only what's pending."

  • Move users in bulk, then clean house. Don't remove people one at a time from the Users tab. Add the role column, group by role, select the whole group, and use Assign Roles — checking only the modules you want to change. The roles table shows user counts, so delete any role sitting at zero.


Related Content

Did this answer your question?