Custom roles
Define permission sets beyond Uniportal's built-in roles.
The built-in roles, Owner, Admin, Manager, Engineer, and Helpdesk, cover most teams, but they're broad by design. When someone's job is a slice of what a built-in role allows, not the whole thing, a custom role lets you define exactly which parts of Uniportal they can see and act on.
When to use one
A few real cases:
- Toby in HR needs read access to tickets for compliance reviews, not the ability to run Agent Tools or touch billing.
- A Tier 1 technician should work tickets through AI Chat but shouldn't manage team members or connect new integrations.
- A billing contact needs Plans & Billing access and nothing else.
If a built-in role already matches what someone needs, use it. Custom roles exist for jobs that don't map cleanly to any built-in role, not as a replacement for one of them.
What a custom role controls
A custom role has two separate sets of permissions.
Uniportal controls what someone can do inside Uniportal itself: manage the team, connect integrations, edit Skills, and so on. Each area, Integrations, AI Chat, Team & Roles, and Plans & Billing, can be set to no access, view-only, or full management.
Agent Tools controls which tools the AI can use on that role's behalf, tool by tool, separately from what the role can do in Uniportal itself. You can let a role view a customer's Pax8 subscriptions through AI Chat without giving it the tool that deletes one, or grant it every NinjaOne tool but none of your billing tools. See Agent Tools for how that list is organized.
Between the two, you can build a role as narrow or broad as the job actually requires.
Creating a custom role
Open Team & Roles
Go to Team & Roles > Roles and select New role.
Name it for the job, not the person
Name the role after what it's for, "Billing contact," "Tier 1 technician," so it still makes sense after the original person who needed it has moved on.
Set the Uniportal permissions
Go through each area, Integrations, AI Chat, Team & Roles, Plans & Billing, and set the access level. Leave anything the role doesn't need at no access, rather than granting view access just in case.
Set the Agent Tools permissions
Grant the specific tools this role should have the AI use on its behalf. Leaving a tool out is the same as denying it, so only add what the job actually needs.
Assign it
Apply the role to an existing team member, or select it when you invite a new one.
Editing and removing custom roles
Editing a custom role changes access for everyone currently assigned to it, immediately. If five technicians share a role, changing it changes access for all five at once, so treat that edit with the same care you'd give a change to a built-in permission. Built-in roles can't be edited or deleted. A custom role can be edited freely and deleted once no one is assigned to it.