Platform
Platform Roles
Inspect fixed platform roles, permission matrices, and bound accounts.
What this menu does
Explain what each fixed role can see and do, and move accounts to the correct role.
Where to find it
Platform Admin navigation: Accounts & Security → Platform Roles.
When to use it
- Review a role's menu and action access.
- See which accounts use a role.
- Assign multiple accounts to a role.
Before you begin
- Sign in to Platform Admin.
- The account must be allowed to view this menu.
Page regions
- 01Role list
- 02Role detail dialog
- 03Permission matrix
- 04Bound-account list
- 05Assign accounts dialog
Supported operations
Inspect a role
- 1
Select View detail on the role.
- 2
Review its description and permission matrix grouped by top-level menu, page, and action.
- 3
Review bound accounts and their status.
- 4
Close the dialog without making changes.
You can identify the business reach of the fixed role.
Assign accounts to a role
- 1
Select Assign accounts for the target role.
- 2
Review existing members and select the required accounts.
- 3
Confirm that selected accounts will move from their current role.
- 4
Save the assignment and verify the account count.
Selected accounts use the target role's fixed permission set.
Business rules and fields
- The permission matrix is read-only on this page.
- Assigning an account to a role moves it; it does not merge two roles.
- Existing role members stay selected unless explicitly changed.
States you may see
What happens next
- Role membership and visible account counts match the saved assignment.
Common problems
The menu or action is missing.
The account does not have the required platform access or the item is not available in the current state.
Ask a platform administrator to verify the account role and the record status.
A save or load action fails.
The session may have expired, validation may have failed, or the service is temporarily unavailable.
Keep the shown request identifier if present, refresh once, correct highlighted fields, and retry. Escalate with the request identifier if it repeats.