Skip to main content

Custom Role Permissions

Custom Role Permissions lets Global Admins turn capabilities on or off for each role, per organization — no engineering request or release wait required.

Written by Liza

Custom Role Permissions lets you shape Kadence around how your organization actually works. Instead of every role having a fixed set of permissions, you decide what each role can do for your company — turning capabilities on or off from a single settings screen, with no engineering request and no waiting for a release.


Before You Start

  • You need the Manage roles and permissions permission to view or edit it. By default this permission lies with Global Admins only.

  • Changes apply to your organization only. There is no shared template across customers.

  • Changes take effect on the user's next action. When someone next loads a page or makes a request, Kadence works out their permissions from your customized setup.

  • You're customizing existing roles, not building new ones. Creating brand-new roles from scratch isn't part of this feature.

Don't see Roles & permissions in your settings? Check that Custom Role Permissions is enabled for your organization and that you hold the Manage roles and permissions permission. Your Customer Success Manager can confirm both.


How It's Organized

Everything lives in one place: Settings > Roles & permissions. The screen opens on Manage roles and has two sub-tabs that share a single set of staged changes and one save bar, so edits across both tabs save together in one go:

  • Manage roles — switch roles your organization uses on or off.

  • Permission matrix — tune what each enabled role can do.

Rather than hundreds of individual switches, related permissions are grouped into capability blocks. A block bundles everything needed for one job — managing visitors, say, or running workplace events — so you reason about what a role can do, not about technical permission names.

There are currently 43 capability blocks across 11 capability areas:

  • Bookings

  • Buildings; floors and spaces

  • Visitors

  • Workplace events

  • People; teams and schedules

  • Workplace safety

  • Communications and support

  • Insights and reporting

  • Devices and kiosks

  • Integrations and API

  • Company and platform.

Each block, for each role, sits in one of three states:

  • Always on — part of the role's core job and can't be switched off.

  • Always off — can never be granted to that role.

  • Editable — yours to turn on or off.


Tune What a Role Can Do (Permission Matrix)

The Permission matrix sub-tab is a grid of your roles against the capability blocks.

  1. Go to Settings and select Roles & permissions.

  2. Open the Permission matrix sub-tab.

  3. Find the role's column and the capability block you want to change.

  4. Toggle the block on or off. If a block is always on or always off for that role, its cell shows a padlock and can't be changed — hover it to see why.

  5. Make as many changes as you like, then click Save changes to apply them, or Discard changes to throw them all away.

Permission matrix

A common use is tightening access — turn off any editable block a role shouldn't have for your organization, such as removing a Building Admin's access to directory sync settings when that sits with a central team.

The Global Admin role doesn't appear in the matrix at all. Its permissions are fixed, which guarantees your organization always has a fully-capable admin.


Spot and Undo Your Customizations

You don't have to remember every original setting — the matrix tracks your deviations from Kadence's defaults for you.

  • Spot them: every changed cell carries a small dot marker, and the toolbar counts them (e.g. 3 customized from defaults). The Customized only filter hides everything else.

  • Undo one: click the reset arrow beside a customized cell to restore that block to the role's standard default.

  • Nothing happens until you save: reverts are staged like any other edit.

Custom role

There's no whole-role or whole-tenant "reset everything" action — you reset cell by cell, so you never lose more customization than you intend.


Review Newly-Added Capabilities

As Kadence grows, new capability blocks are added over time. Any block added since you last reviewed your permissions carries a New badge.

  • Review each new block and set it on or off for the roles that should have it.

  • Click Mark reviewed in the toolbar to clear the badges. Saving permission changes doesn't clear them on its own — review is always a separate, explicit step.

New tag

The review state is shared across your organization, not per person. When one Global Admin clicks Mark reviewed, it clears for everyone. Badges never clear on a timer — they stay until someone reviews them.


Turn Off Roles You Don't Use (Manage Roles)

If your organization doesn't use a particular role, switch it off so it stops granting access.

  1. Open the Manage roles sub-tab. Roles show as cards in two groups: Primary roles (every member holds exactly one) and Add-on roles (optional, layered on top).

  2. Switch off any role you want to disable. You can disable: Building Admin, Coordinator, Event Organizer, Workplace Safety Admin, and Booking Scheduler.

  3. If anyone currently holds that role, a confirmation shows how many people are affected.

  4. Click Save changes to commit, or Discard changes to revert.

Manage roles

Disabling a role is irreversible for assignments. It removes the role from everyone who holds it. Re-enabling the role later makes it assignable again, but it does not restore who had it — those people need to be reassigned by hand. Check each role's member count before you commit.

A few things to note:

  • Employee can't be disabled — it shows an "Always on" label instead of a switch.

  • Global Admin isn't listed at all and can't be edited or disabled.

  • Team Manager is marked "Derived from team membership" and follows who manages a team, so it can't be switched off either.

  • No user is ever left without a role — if disabling a role would leave someone with none, Kadence keeps them on the Employee baseline.

  • Disabling Workplace Safety Admin never reduces a Global Admin's access — Global Admins keep their safety capabilities regardless.

  • Disabled roles drop out of the Permission matrix automatically, with a note telling you how many are hidden.


Grant Admin Roles from Your Directory (Directory Sync)

If you manage identity via Directory Sync, you can let group membership confer Kadence admin roles automatically — so adding someone to a security group makes them an admin, and removing them takes it away, with no per-user assignment in Kadence.

  1. Go to Settings > Integrations > Directory Sync.

  2. Open the Role mappings sub-tab.

  3. Click Add mapping and pick a directory team and the admin role it should confer. You can map to Global Admin, Building Admin, or Coordinator.

  4. Save. From then on, membership of that team confers the role — and leaving it (or deleting the group or mapping) removes it automatically, on the user's next action.

Map directory synced teams

Add Kadence Role

Good to know about directory-mapped roles:

  • A user who gets Global Admin through a group can do everything a manually-assigned Global Admin can.

  • A user who gets Building Admin through a group holds the role but administers no buildings until a Global Admin assigns specific buildings to them.

  • If someone belongs to more than one mapped team, they receive the highest-privilege role — privilege runs Global Admin, then Building Admin, then Coordinator.

  • Only these three admin roles can be mapped. Employee, Team Manager, and the add-on roles can't be.


How the Team Manager Role Works

Team Managers get their capabilities automatically — there's nothing to set up. When someone becomes responsible for managing a team, Kadence gives them a team-scoped role that applies only to the teams they manage, not the wider organization.

This role is deliberately limited to a small, fixed set of capabilities:

  • Manage their team's bookings

  • Export their team's bookings

  • See team-manager insights

  • Manage their own surveys

  • Manage their own announcements

Everything else is held off, so managing a team never quietly grants organization-wide power. A Global Admin can fine-tune the editable capabilities in this column, but the role can never be given unrelated permissions, can't be disabled, and is never assigned directly.


Good to Know

  • Everything saves together. The Permission matrix and Manage roles tabs share one staged set of changes and one save bar.

  • Every change is audited. Each block you toggle and each role you enable or disable is recorded — available on request through your Customer Success Manager.

  • Customization is per role, not per person. Setting different permissions for individual users isn't part of this feature.


FAQs

Why can't I turn off a particular capability for a role?

That block is set to always on for that role — it's part of the role's core job and is protected so the role is never left unable to do essential work. Blocks set to always off work the same way in reverse.

Why doesn't the Global Admin role appear in the matrix?

Global Admin is deliberately non-editable so your organization always has a fully-capable top-level administrator. Because nothing about it can change, it isn't shown as a column at all.

I made a change but a user still has their old access. Why?

Permissions are worked out when a user next acts in Kadence. Ask them to refresh or take their next action, and the updated permissions will apply.

What happens if Custom Role Permissions is switched off for us?

Every role instantly reverts to Kadence's standard built-in permissions (roles you've disabled stay disabled). Nothing is migrated and no configuration is lost — if it's switched back on, your customized setup returns as it was. The one exception is role assignments removed by disabling a role — those aren't restored either way.

If I disable a role, can I get the assignments back by switching it on again?

No. Disabling a role removes it from everyone who holds it, and that can't be undone by re-enabling — re-enabling only makes the role assignable again. Check the member count before you disable, and be ready to reassign people if you switch it back on.

Can I create a brand-new role from scratch?

Not with this feature. Custom Role Permissions tailors the roles Kadence already provides. Building entirely new roles is a separate capability.

Can I map a directory group to any role?

Only the three admin roles — Global Admin, Building Admin, and Coordinator. Other roles can't be mapped from your directory.

My directory-mapped Building Admin can't manage any buildings. Why?

A group-conferred Building Admin holds the role but administers no buildings until a Global Admin assigns specific buildings to them. The role on its own doesn't grant building-specific access.


Need Help?

For a full breakdown of what each built-in role can access by default, see User Role Permissions.

For support, reach out to:
📩 [email protected]

For more helpful articles see:
📚 Kadence Help Center

Did this answer your question?