⭐ What custom roles are
Access in Matter Management relies on three standard roles: Administrator, Contributor and Reader. That model is simple, but it rarely matches how a legal team is actually organised. Some people need slightly less access than a role gives them, and the usual workarounds are to over-grant permissions or to stretch a role beyond its purpose, which creates security exposure and day-to-day confusion about who is allowed to do what.
A custom role is a named permission set built from one of those three standard roles. It keeps the permissions your team genuinely needs and drops the rest, so each person gets the access their job requires and nothing more.
A few principles are worth knowing:
- The three standard roles — Administrator, Contributor and Reader — are fixed. They cannot be created, renamed or deleted, and their permissions cannot be edited.
- Every custom role is derived from one of those three standard roles, called its role type.
- A custom role can only restrict. It removes permissions from its role type; it can never grant a permission the role type does not already hold.
- Each user is assigned exactly one role, standard or custom.
- The role type is fixed once the role is created. A role that needs a different baseline has to be set up as a new role.
- Role definitions are stored centrally for the whole DiliTrust suite, so a role is always the same wherever it is consulted.
☝ How to get a custom role
Custom roles are set up for you by DiliTrust. To request one, contact your DiliTrust Account Manager, who will arrange it with the Customer Success team.
To make the request straightforward, have the following ready:
- The standard role the new role should be based on: Administrator, Contributor or Reader. Choose the one just above the access level you have in mind, since a custom role can only remove permissions.
- A name for the role. It has to be unique within your organisation, and names are compared without regard to upper or lower case.
- A short description of up to 255 characters. It is optional, but it saves your colleagues from guessing what the role is for.
- The list of permissions that should be removed. The next section covers what can be adjusted.
- The users who should hold the role.
The same route applies to changing a custom role, duplicating one to create a close variant, or deleting one you no longer need.
✅ What you can restrict
Permissions are organised by topic. The following can be removed from a custom role:
- Matters — access matter (overview, details, documents, custom tabs, quickview, tasks); create a new matter; edit a matter (incl. permissions); delete a matter; export matters
- Provisions — access provisions; add and edit a provision entry; export provisions
- Spend — access matter spends; create a new matter spend; edit a matter spend; delete a matter spend
- Requests — access, edit, create, delete and export requests
- Contacts — create, modify and delete contacts; access the list of contacts; import a list of contacts
- Statistics — access statistics
- Roles and users — edit roles permissions; add, disable and edit users
- Teams — create, edit and delete teams
- Configuration — access the configuration panel; access matter types configuration; edit matter types configuration
Two rules shape what a valid custom role looks like:
- Some permissions depend on others. When a parent permission is removed, the permissions that depend on it are removed with it.
- A subset of Administrator permissions cannot be removed. This guarantees that an Administrator-derived role always keeps enough access to manage the application.
Permission changes reach the people holding the role the next time they load a page. Nobody needs to log out and log back in.
⛔ What your users see when access is restricted
If a user opens a matter and their role gives them access to none of its sections, the matter content is replaced by a full-page message telling them access is restricted. The top bar stays visible, so they still see the matter name, the breadcrumb and the status, and can navigate away easily. This is intentional: people understand that a restriction applies rather than thinking the page is broken or the matter is empty.
✨ Tips and best practices
- Start from the closest standard role. Because custom roles only restrict, pick the role type that sits just above the access level you want, then list what should come off.
- Grant the minimum access each job genuinely requires. It is the simplest way to reduce exposure, and it removes the grey areas that lead to permission misuse.
- Always provide a description. It travels with the role and tells your colleagues what it is for.
- Name roles after responsibilities rather than individuals, so the role survives people joining and leaving.
- When two roles differ by only a few permissions, ask for a duplicate of the first one rather than describing the whole set again.
- Protect reporting quality. If broken reporting data is a concern, keep the matter deletion permission with your Administrators and remove it from roles that do not strictly need it.
- Group your requests. Reviewing who needs what across the whole team at once is faster than raising roles one by one.
❕ Limitations and known constraints
- Custom roles are restrictive only. A custom role can never hold a permission its role type does not already have.
- Each user has exactly one role. Combining several roles on the same user is not supported.
- The role type of a custom role is fixed once the role is created and cannot be changed afterwards.
- Deleting a custom role is permanent and cannot be undone.
- A subset of Administrator permissions cannot be removed.
- At least one active standard Administrator must always remain in your instance.
- The three standard roles cannot be created, edited, renamed or deleted.
- Permission changes are not applied to a connected user instantly; they take effect on their next page load.
❓ Frequently asked questions
Who do I contact to set up a custom role?
Your DiliTrust Account Manager. They work with the Customer Success team to create, modify or remove custom roles for your organisation.
Can I give a custom role more access than the standard role it comes from?
No. Custom roles can only remove permissions from their role type, never add to them. If you need broader access, base the role on a higher role type instead.
Can the role type of an existing custom role be changed?
No. The role type is fixed once the role is created. A new role has to be set up with the correct role type, and your users reassigned to it.
Can a user hold two roles at the same time?
No. Each user is assigned exactly one role. A custom role covering the combination of responsibilities you need is the way to handle this.
Why can't the Administrator, Contributor or Reader role be edited?
The three standard roles are fixed baselines for the whole platform. A tailored permission set is obtained by creating a custom role derived from the standard role closest to what you need.
Why can some Administrator permissions not be removed?
A subset of Administrator permissions is mandatory. This prevents an Administrator-derived role from ending up without enough access to manage the application.
When do permission changes reach my users?
The next time they load a page. Users who are already connected do not need to log out and log back in.
Why don't I see custom roles on the Roles page in Matter Management?
The Roles page in Matter Management shows the three standard roles and their permissions. Custom roles are set up by DiliTrust on request, so contact your Account Manager rather than looking for a creation option there.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article