Manage site roles
This is Console-only. Open the target site, select Authentication, then Site Roles.
Before you begin
Create the required App Roles first; a Site Role only bundles existing App Roles. Confirm the selected site and app-role scope before creating a default role, because default assignment affects new site users.
- Select Create Site Role, enter Name and Description, and choose Default Role only when every new site user should receive it.
- Under Bundled App Roles, select the app roles that the site role grants.
- Select Create Site Role, then verify its bundle and assigned users in the Site Roles list before broad use.
- Select Manage Users to assign or remove site users, then verify the user list and resulting app access.
- Edit the role from the same list and select Save Changes. Name cannot be changed after creation; recheck its bundled app roles and users.
If a bundled App Role is unavailable, return to the app role definition and create or correct it before retrying. If user assignment fails, verify the user belongs to the selected site and refresh the Site Roles list before retrying. Use Assign user access for membership assignment or revocation after the Site Role is ready.
- Affected resource and cascade: Review assigned users and bundled app roles; memberships are removed when the role is deleted, while bundled App Role definitions remain.
- Reversibility: Delete Site Role cannot be undone.
- Authorization: Confirm the selected site and that you are allowed to make this change.
- Backup or export: Note the role's bundled app roles and assigned users.
- Confirmation: Confirm this exact Site Role.
- Success response and postcondition: Verify it no longer appears and affected users no longer hold its membership.
- Recovery: Recreate the role and reassign its users.
Select Delete Site Role only after completing these controls. Site roles can be managed only in the Console.
For unresolved role lifecycle failures, see troubleshooting.