Vettero
Configuration

Roles

Nested workspace roles for access control and approval gating.

Roles are custom workspace identities used for permission matrices and human-in-the-loop approvals. You can nest roles up to three levels (L1–L3). They are separate from membership flags such as Owner and Developer, which control who can manage the workspace and see Dev-only menus.

Use them when tables, widgets, in-app channels, or agent tools should be limited to specific groups of members.

When to use

  • Restrict table or column access by role
  • Nest org roles (parent → child) for inheritance-friendly permission setup
  • Gate agent tools with Require role approval

Create a role

Open Configuration → Workspace Settings → Roles.

  1. Choose Create Role, or add a child with + on a role that is below level 3.
  2. Set Name (max 100 characters), optional Description, and optional Parent Role.
  3. Save. Parent cannot change after create.
SettingWhat it does
NameUnique label in the workspace
DescriptionOptional notes
Parent RoleEmpty for a root (L1) role; otherwise nests under a parent (max depth 3)

Owners can open Users on a role to assign or remove workspace members. Viewing and assigning users on roles is Owner-only; Developers can manage role definitions depending on settings access.

How roles differ from Owner / Developer

ConceptPurpose
Owner / DeveloperAccount membership on the workspace — admin surfaces, Dev-gated sidebar items
Custom rolesResource permissions (tables, fields, widgets, in-app View) and approval assignees

A person can be a Developer and also hold one or more custom roles.

Where roles apply

PlaceHow
Tables / columnsRole permission grids for read/write access
Widgets / In App chatRole-based access (View on in-app chat integrations)
Agent toolsRequire role approval — members with those roles approve on Approvals (or in-chat when they are the current user). See Approval flow.
Request InformationCollect answers from role holders before a run continues

Limits

  • Maximum nesting depth is 3 levels.
  • Role names must be unique in the workspace.
  • Parent is locked after create; create a new role if you need a different parent.

Where roles are used

PlaceHow
Tables, widgets, in-app chatAccess matrices
ApprovalsRole-based tool and step gating — see Approval flow
Copyright © 2026