Custom Role Permissions lets you shape Kadence around how your organization actually works. Instead of every role having a fixed set of permissions, you decide what each role can do for your company — turning capabilities on or off from a single settings screen, with no engineering request and no waiting for a release.
Before You Start
You need the Manage roles and permissions permission to view or edit it. By default this permission lies with Global Admins only.
Changes apply to your organization only. There is no shared template across customers.
Changes take effect on the user's next action. When someone next loads a page or makes a request, Kadence works out their permissions from your customized setup.
You're customizing existing roles, not building new ones. Creating brand-new roles from scratch isn't part of this feature.
Don't see Roles & permissions in your settings? Check that Custom Role Permissions is enabled for your organization and that you hold the Manage roles and permissions permission. Your Customer Success Manager can confirm both.
How It's Organized
Everything lives in one place: Settings > Roles & permissions. The screen opens on Manage roles and has two sub-tabs that share a single set of staged changes and one save bar, so edits across both tabs save together in one go:
Manage roles — switch roles your organization uses on or off.
Permission matrix — tune what each enabled role can do.
Rather than hundreds of individual switches, related permissions are grouped into capability blocks. A block bundles everything needed for one job — managing visitors, say, or running workplace events — so you reason about what a role can do, not about technical permission names.
There are currently 43 capability blocks across 11 capability areas:
Bookings
Buildings; floors and spaces
Visitors
Workplace events
People; teams and schedules
Workplace safety
Communications and support
Insights and reporting
Devices and kiosks
Integrations and API
Company and platform.
Each block, for each role, sits in one of three states:
Always on — part of the role's core job and can't be switched off.
Always off — can never be granted to that role.
Editable — yours to turn on or off.
Tune What a Role Can Do (Permission Matrix)
The Permission matrix sub-tab is a grid of your roles against the capability blocks.
Go to Settings and select Roles & permissions.
Open the Permission matrix sub-tab.
Find the role's column and the capability block you want to change.
Toggle the block on or off. If a block is always on or always off for that role, its cell shows a padlock and can't be changed — hover it to see why.
Make as many changes as you like, then click Save changes to apply them, or Discard changes to throw them all away.
A common use is tightening access — turn off any editable block a role shouldn't have for your organization, such as removing a Building Admin's access to directory sync settings when that sits with a central team.
The Global Admin role doesn't appear in the matrix at all. Its permissions are fixed, which guarantees your organization always has a fully-capable admin.
Spot and Undo Your Customizations
You don't have to remember every original setting — the matrix tracks your deviations from Kadence's defaults for you.
Spot them: every changed cell carries a small dot marker, and the toolbar counts them (e.g. 3 customized from defaults). The Customized only filter hides everything else.
Undo one: click the reset arrow beside a customized cell to restore that block to the role's standard default.
Nothing happens until you save: reverts are staged like any other edit.
There's no whole-role or whole-tenant "reset everything" action — you reset cell by cell, so you never lose more customization than you intend.
Review Newly-Added Capabilities
As Kadence grows, new capability blocks are added over time. Any block added since you last reviewed your permissions carries a New badge.
Review each new block and set it on or off for the roles that should have it.
Click Mark reviewed in the toolbar to clear the badges. Saving permission changes doesn't clear them on its own — review is always a separate, explicit step.
The review state is shared across your organization, not per person. When one Global Admin clicks Mark reviewed, it clears for everyone. Badges never clear on a timer — they stay until someone reviews them.
Turn Off Roles You Don't Use (Manage Roles)
If your organization doesn't use a particular role, switch it off so it stops granting access.
Open the Manage roles sub-tab. Roles show as cards in two groups: Primary roles (every member holds exactly one) and Add-on roles (optional, layered on top).
Switch off any role you want to disable. You can disable: Building Admin, Coordinator, Event Organizer, Workplace Safety Admin, and Booking Scheduler.
If anyone currently holds that role, a confirmation shows how many people are affected.
Click Save changes to commit, or Discard changes to revert.
Disabling a role is irreversible for assignments. It removes the role from everyone who holds it. Re-enabling the role later makes it assignable again, but it does not restore who had it — those people need to be reassigned by hand. Check each role's member count before you commit.
A few things to note:
Employee can't be disabled — it shows an "Always on" label instead of a switch.
Global Admin isn't listed at all and can't be edited or disabled.
Team Manager is marked "Derived from team membership" and follows who manages a team, so it can't be switched off either.
No user is ever left without a role — if disabling a role would leave someone with none, Kadence keeps them on the Employee baseline.
Disabling Workplace Safety Admin never reduces a Global Admin's access — Global Admins keep their safety capabilities regardless.
Disabled roles drop out of the Permission matrix automatically, with a note telling you how many are hidden.
Grant Admin Roles from Your Directory (Directory Sync)
If you manage identity via Directory Sync, you can let group membership confer Kadence admin roles automatically — so adding someone to a security group makes them an admin, and removing them takes it away, with no per-user assignment in Kadence.
Go to Settings > Integrations > Directory Sync.
Open the Role mappings sub-tab.
Click Add mapping and pick a directory team and the admin role it should confer. You can map to Global Admin, Building Admin, or Coordinator.
Save. From then on, membership of that team confers the role — and leaving it (or deleting the group or mapping) removes it automatically, on the user's next action.
Good to know about directory-mapped roles:
A user who gets Global Admin through a group can do everything a manually-assigned Global Admin can.
A user who gets Building Admin through a group holds the role but administers no buildings until a Global Admin assigns specific buildings to them.
If someone belongs to more than one mapped team, they receive the highest-privilege role — privilege runs Global Admin, then Building Admin, then Coordinator.
Only these three admin roles can be mapped. Employee, Team Manager, and the add-on roles can't be.
How the Team Manager Role Works
Team Managers get their capabilities automatically — there's nothing to set up. When someone becomes responsible for managing a team, Kadence gives them a team-scoped role that applies only to the teams they manage, not the wider organization.
This role is deliberately limited to a small, fixed set of capabilities:
Manage their team's bookings
Export their team's bookings
See team-manager insights
Manage their own surveys
Manage their own announcements
Everything else is held off, so managing a team never quietly grants organization-wide power. A Global Admin can fine-tune the editable capabilities in this column, but the role can never be given unrelated permissions, can't be disabled, and is never assigned directly.
Good to Know
Everything saves together. The Permission matrix and Manage roles tabs share one staged set of changes and one save bar.
Every change is audited. Each block you toggle and each role you enable or disable is recorded — available on request through your Customer Success Manager.
Customization is per role, not per person. Setting different permissions for individual users isn't part of this feature.
FAQs
Why can't I turn off a particular capability for a role?
Why can't I turn off a particular capability for a role?
That block is set to always on for that role — it's part of the role's core job and is protected so the role is never left unable to do essential work. Blocks set to always off work the same way in reverse.
Why doesn't the Global Admin role appear in the matrix?
Why doesn't the Global Admin role appear in the matrix?
Global Admin is deliberately non-editable so your organization always has a fully-capable top-level administrator. Because nothing about it can change, it isn't shown as a column at all.
I made a change but a user still has their old access. Why?
I made a change but a user still has their old access. Why?
Permissions are worked out when a user next acts in Kadence. Ask them to refresh or take their next action, and the updated permissions will apply.
What happens if Custom Role Permissions is switched off for us?
What happens if Custom Role Permissions is switched off for us?
Every role instantly reverts to Kadence's standard built-in permissions (roles you've disabled stay disabled). Nothing is migrated and no configuration is lost — if it's switched back on, your customized setup returns as it was. The one exception is role assignments removed by disabling a role — those aren't restored either way.
If I disable a role, can I get the assignments back by switching it on again?
If I disable a role, can I get the assignments back by switching it on again?
No. Disabling a role removes it from everyone who holds it, and that can't be undone by re-enabling — re-enabling only makes the role assignable again. Check the member count before you disable, and be ready to reassign people if you switch it back on.
Can I create a brand-new role from scratch?
Can I create a brand-new role from scratch?
Not with this feature. Custom Role Permissions tailors the roles Kadence already provides. Building entirely new roles is a separate capability.
Can I map a directory group to any role?
Can I map a directory group to any role?
Only the three admin roles — Global Admin, Building Admin, and Coordinator. Other roles can't be mapped from your directory.
My directory-mapped Building Admin can't manage any buildings. Why?
My directory-mapped Building Admin can't manage any buildings. Why?
A group-conferred Building Admin holds the role but administers no buildings until a Global Admin assigns specific buildings to them. The role on its own doesn't grant building-specific access.
Need Help?
For a full breakdown of what each built-in role can access by default, see User Role Permissions.
For support, reach out to:
📩 [email protected]
For more helpful articles see:
📚 Kadence Help Center






