Custom Roles
If none of the six standard roles fits how your team works, build your own. A custom role is a name, a description, and any combination of the 71 permissions.
Custom roles belong to one team. Creating one in Team A does not put it in Team B.
Creating One
- Sign in to hub.twominutereports.com and select your team
- Go to Settings → Roles
- Click New role
- Give it a name (up to 64 characters) and a description (up to 255)
- Tick the permissions it should include — they are grouped by area, and each has a tooltip saying what it actually does
- Click Create role
The role is then available in the role dropdown everywhere you assign one.
Viewing Is Always Included
The View permissions are ticked for you and cannot be turned off. A custom role decides what somebody can change, not what they can see.
This is not a limitation of the builder — it is how the product works. Several screens fetch connections, queries, schedules and setup state in a single request and cannot answer part of it, so a "View connections" switch you could turn off would hide the connections page and still show the same connections in the Sheets add-on. A control that works in one place and quietly fails in another is worse than no control, so we do not offer one.
If somebody genuinely must not see a client's data, a custom role is the wrong tool. Share a single dashboard with a share link instead, or send a setup link so they can connect their own accounts without joining the team at all.
Some Roles Worth Building
Reporting Analyst — an Editor who can also run queries but cannot delete anything. Useful when several people share the same sheets and an accidental delete is the thing you actually worry about.
Client Onboarder — connections, connected accounts and clients, without dashboards. For contractors who set data up and hand it over.
Billing Contact — the plan and invoices, and no ability to change anything else. For a finance colleague who needs to see what you spend. They will still be able to view the team's reports and connections, because viewing is always included.
Read-only plus briefings — viewing, plus sending a briefing, and nothing else editable. For an account manager who reports to clients but never builds.
The One Rule: You Can Only Grant What You Hold
You cannot create or edit a role that includes a permission you do not have yourself.
In the role builder, permissions you do not hold appear locked, with a lock icon and an explanation — not hidden. Seeing that a permission exists and that you cannot grant it is the whole point: hiding it would turn a rule into a mystery, and you would not know to ask.
The reason is simple. If a Deputy Admin could build a role containing Change the plan and pay, they could assign it to themselves — or to a friendly colleague — and have exactly the permission the product withheld from them. Every permission model has to close that door, and this is where this one closes it.
The Other Three Rules
These govern assigning roles rather than building them, and they apply to standard and custom roles alike.
You cannot give someone a role bigger than your own. The role you assign must be one whose permissions you hold, for the same reason as above.
You cannot change someone whose role is not smaller than yours. Two Deputy Admins cannot re-role each other, and nobody can re-role an Admin from below. Roles are only editable downwards, and "equal" counts as not-below — otherwise two colleagues with identical roles could demote each other.
The account Owner is the exception: they can change or remove anybody. Admin holds exactly the same permissions as Owner, so without that exception the person who pays could not manage their own Admins.
You cannot change your own role or seat. Not even to reduce it. Self-service demotion sounds harmless until it is the last Admin doing it by accident, and then there is nobody left who can undo it.
The Owner is outside all of it. The Owner cannot be re-roled or removed by anyone, including another Admin. It follows the account, not a role assignment — contact support to change who it is.
Deleting a Custom Role
You can only delete a role that nobody holds. Re-assign the members first — that way a deletion never silently drops someone's access to whatever the role happened to include.
The six standard roles cannot be deleted or edited.
Custom Roles and Seats
A custom role is subject to seats like any other. If it contains permissions marked Yes in the Seat column of the matrix, the member needs a seat before those take effect.
Since viewing is always included and no View permission is seat-gated, a custom role with no editing permissions at all works fully without a seat — so it costs nothing to hand out. Adding any permission that changes something is what makes a seat necessary.
Seats
A seat is permission to change things in one team. What a seatless member can still do on every surface, what is refused, and why scheduled refreshes never stop.
Managing Members
Invite people, change a role, assign and un-assign seats, and remove a member — including what happens to the dashboards and reports they built.