Open Roles And Permissions
- Open Admin.
- Choose Roles.
- Review the role list.
- Use Duplicate on a system role or Create custom role when the defaults do not fit.

Roles and Permissions shows locked system roles, custom roles, permission counts, assigned users, and safe duplicate or edit actions.
Understand System And Custom Roles
- System roles are Arcus defaults. They are locked so updates stay consistent.
- Custom roles are entity-specific access profiles created by your admins.
- Assigned users show whether a role is actively used.
- Permission count helps compare broad roles to narrow roles.
Create A Custom Role
- Choose Create custom role, or duplicate a locked system role.
- Enter a name that matches the job, such as AP Clerk, Shipping Lead, or Inventory Auditor.
- Add a short description so future admins know why the role exists.
- Review each permission group.
- Select only the permissions required for the user’s real work.
- Save the role.
- Assign it from Organization Users or Entity Team.
- Review the Role Coverage Report after assignment.

The role editor groups permission keys so admins can build the role around actual work instead of guessing from one long list.
Permission Groups To Review Carefully
Use a second reviewer for high-risk roles when possible.
Assign Roles Safely
Roles are assigned from user management surfaces.- Use Organization Users when inviting a person or managing entity memberships.
- Use Entity Team for day-to-day role changes inside the active entity.
- Use Location Access when the user should only work in certain warehouses or locations.
- Use Custom Permissions only when a one-off override is truly needed.
Use Role Coverage Report
Open Admin, then Role Coverage Report. The report shows active users, their role, custom role, and effective permissions after role defaults and overrides are applied.
Role Coverage helps admins confirm who has each permission after role defaults and user-level overrides are combined.
- Onboarding review after assigning a role.
- Offboarding review before removing final access.
- Quarterly access review.
- Troubleshooting a permission-denied report.
- Confirming custom overrides did not grant more access than intended.
- CSV review when a compliance reviewer needs the effective permission matrix outside Arcus.
Troubleshoot Permission Problems
Common Blocks
- System role cannot be edited: duplicate it, then edit the custom copy.
- Save is disabled: role name is required.
- Permission key is confusing: compare it with the page or action the user needs, then verify with Role Coverage.
- User has access in sandbox but not production: roles are assigned per entity.
- New location is invisible to a user: update location access after adding the location.
- Role cleanup is overdue: export or review Role Coverage, remove stale overrides, and deactivate unused custom roles only after users are reassigned.
Related Articles
User Management
Invite users, assign entity access, restrict locations, reset MFA, and manage current entity users.
Organization, Entities, and API Access
Manage organization overview, entities, user access, and organization-level safety controls.
Audit Log and Compliance
Review audit activity, compliance reports, saved filters, and user access history.
Profile and Security
Manage your own profile, PIN, MFA factors, security keys, and recovery options.

