- Only the MA can create custom roles.
- A custom role can only inherit the subset of permissions from a single role. In other words, a custom role cannot inherit permissions from two different roles.
For example, you cannot create a custom UA role that has permissions to manage users (UA permission) and create organizations (OA permission.)
- You cannot assign new permissions to a custom role, if the parent role does not have these permissions.
For example, if the predefined OA role does not have the permission to create an organization, then the custom role that is based on this OA role cannot have that permission.
- When you create a custom role, a task representing one or more permissions will continue to be visible, as long as at least one of the permissions is still available.
For example, the "Search Organizations" link will appear if the Update permission is still available, even though the Activate, Deactivate, and Delete permissions are disabled.
- A new custom role is available to other instances of Administration Console only after you refresh the server cache (see "Refreshing a Server Instance").