Roles control what each person can do in Pirros — who can upload, download, edit, manage content, and change settings. This article explains how roles work and gives a plain-English description of every permission, so you can build exactly the role you want.
In a hurry? The single most important thing to know: some permissions always apply to your whole firm, and the rest apply only to one workspace. Jump to Firm-wide permissions below to see which is which — that's what determines whether a role can reach outside a single workspace.
First: does your firm use Workspaces?
How roles behave depends on whether your firm has Workspaces turned on. Figure out which setup you're in — it changes everything below.
If your firm does NOT use Workspaces
You have one library. Each person is given one role, and it applies everywhere.
Scope doesn't come into play — every permission you grant applies across your whole firm.
You can ignore the workspace-only permissions (Workspaces, Edit Workspace Settings, Workspace Views) — they only appear once Workspaces is enabled.
If your firm DOES use Workspaces
You assign each person a role inside each workspace they belong to. The same person can be an Admin in one workspace and a Member in another.
Most permissions are per-workspace — they only affect the workspace where you granted the role. Give someone the "Delete Details" permission in the Interiors workspace and they can't delete anything in Structure.
A handful of permissions are always firm-wide — they apply across your entire firm no matter which workspace you grant them in. These are listed in the next section.
Building a "workspace admin" (someone who runs their own workspace but can't touch the rest of the firm)? Give them a role with all the library permissions they need — but none of the firm-wide permissions in the next section. That's the whole trick: a role made only of per-workspace permissions can never reach outside the workspace it's assigned in.
Default roles
Every firm starts with four built-in roles. You can use them as-is, or start from one and build a custom role.
Admin — full access to everything: content, users, settings, analytics. Best for firm owners and administrators.
Member — day-to-day access: find and download content, create flags, submit requests, view firm stashes. Cannot upload or see analytics. Best for architects and engineers.
View Only — read-only. Can look at details, projects, families, and firm stashes; can't download, create, edit, or delete. Best for reviewers or consultants.
IT Administrator — user management only (invite, update roles, delete users) with no content access. Best for IT staff who manage accounts but don't use the library.
Firm-wide permissions (always apply to your whole firm)
These permissions always act across your entire firm, even if you grant them inside a single workspace. They're the "run the company" permissions — leave them out of any role that's meant to be limited to one workspace.
Permission | What it lets someone do |
Edit Firm Settings | Change firm-wide settings and display defaults that apply to everyone. |
Manage Product Licenses | Assign and free up paid seats. Granting a seat spends your firm's purchased capacity. |
Invite Users | Invite brand-new people into the firm. This consumes a seat. |
Update User Role | Change what role a person has. (See the FAQ — no one can hand out access they don't have themselves.) |
Delete User | Remove a person from the firm entirely (not just from one workspace). |
Create Custom Roles / Edit Custom Roles / Delete Custom Roles | Create, change, or remove the roles themselves. A role change applies firm-wide to everyone who has that role. |
Create SSO Connection | Set up and configure single sign-on, JIT provisioning, and SCIM for the firm. |
Create Workspaces / Edit Workspaces / Delete Workspaces | Add, rename, or remove workspaces across the firm. |
Manage API Keys | Create and manage the API keys integrations use to connect to your firm. |
Manage Resource Filters | Control what your API integrations are allowed to reach across the firm. |
Library & content permissions (per-workspace)
Everything below is per-workspace if your firm uses Workspaces — it only affects the workspace where the role is assigned. If your firm doesn't use Workspaces, these simply apply across your whole library.
Details (each has a matching Typical Details version for your typical library)
View / Create / Edit / Delete Details | See, upload, change, and remove details. |
Revert Details | Roll a detail back to an earlier version. This changes the active version for everyone — use with care. |
Download Project Details / Download Typical Details | Pull details into a Revit model. |
Download Reference Only | Download reference-only details directly, skipping the request/approval step. |
Upgrade Detail Revit Version | Bring a detail up to a newer Revit version. |
Families (each has a matching Typical Families version)
View / Create / Edit / Delete Families | See, upload, change, and remove families. |
Download Families / Download Families (Reference Only) | Pull families into a model; the reference-only version skips the request step. |
Revert Families | Roll a family back to an earlier version (affects everyone). |
Flag Families | Flag a family for review. |
Upgrade Family Revit Version | Bring a family up to a newer Revit version. |
Projects
Create / View / Edit / Delete Projects | Manage the projects details are organized under. |
Toggle Reference Only | Mark an entire project as reference-only. |
Firm Stashes
Create / View / Edit / Archive / Delete Firm Stashes | Manage shared collections of content that everyone in the workspace can use. |
Organizing: Tags, Filters, Views & Associations
Create / Edit / Delete Tag Definitions | Manage the set of tags people can apply to content. |
Create / Edit / Delete Project Filters | Manage the saved project filters people can use to narrow content. |
Create / Edit / Delete Workspace Views | Manage the shared saved views (search + column layouts) everyone in the workspace sees. |
Manage Associations | Link related details and families together so they surface with one another. |
Source Files & Templates
Create / View / Edit / Delete Source Files | Manage the uploaded source models (.rvt, .rte, .rfa) content comes from. |
View / Create / Download / Delete Templates | Manage Revit template models. |
Flags & Tickets
Create Flags / View Flags (Management) / Resolve Flags | Flag content for attention, review all flags in the Management tab, and resolve them. |
Create Tickets / View Tickets (Management) / Edit Tickets | Submit requests (uploads, reference-only, typical versions), see them in Management, and approve or deny them. |
Insight & Bulk Tools
View Analytics | See usage analytics in the Management tab. |
View Typical Suggestions / Manage Typical Library | See Pirros' suggestions for what to promote to typical, and act on them. |
View Library Health | See the health-score dashboard for the library. |
Bulk Edit | Export content to Excel and bulk-edit tags and notes. |
Edit Workspace Settings
This one deserves a note because it's easy to confuse with the permissions above. Edit Workspace Settings controls who can change that workspace's own Settings screens — how uploads are processed, health-score setup, display/column defaults, and workspace-level management of saved views. It's the workspace's configuration area, and it only affects that one workspace.
That's different from the individual Tags, Project Filters, and Workspace Views permissions above, which control creating and editing those items during everyday library use. Edit Workspace Settings is the "settings page"; those others are the "do it in the library" actions. (Editing firm-wide settings is a separate, firm-wide permission — see Edit Firm Settings above.)
FAQ
Q: Can a user have different roles in different workspaces?
A: Yes (when your firm uses Workspaces). Roles are assigned per workspace — someone can be an Admin in one and a Member in another.
Q: How do I make a workspace admin who can't touch the rest of the firm?
A: Build a custom role that includes the library permissions you want but none of the firm-wide permissions listed above (no Workspaces, SSO, Roles, Users, Firm Settings, Licenses, API Keys, or Resource Filters). Assign it to the person in their workspace. Because every permission in the role is per-workspace, it can't reach any other workspace or any firm setting.
Q: Can someone use "Update User Role" to make another person a firm admin?
A: No. A person can only grant a role whose permissions are a subset of what they themselves have. Nobody can hand out access they don't already hold — so they can't create an admin more powerful than themselves.
Q: Does "Delete User" just remove them from one workspace?
A: No — Delete User removes the person from the firm entirely. To take someone out of a single workspace without removing them from the firm, change their workspace role assignments instead.
Q: Does inviting a user use up a seat?
A: Yes. Invite Users brings a new person into the firm and consumes one of your paid seats. Because it affects firm-wide capacity, it's a firm-wide permission and can't be limited to a single workspace.
Q: How do I create a custom role?
A: See Create Custom User Roles for step-by-step instructions. Start from a default role (Admin, Member, View Only, IT Administrator) and adjust.
Q: What happens if I change a role's permissions?
A: The change takes effect immediately for everyone assigned to that role.
Q: Can I delete a default role?
A: No. The four default roles can't be deleted. You can delete a custom role only when no users are assigned to it.
Q: What does "Revert" mean?
A: Revert rolls a detail or family back to a previous version. It changes the active version for everyone — use with caution.
]]>
