---
title: Adding Roles
slug: zen-master/adding-roles
docTags: 
createdAt: 2024-12-27T19:50:10.737Z
---

**To add a role:**

:::::WorkflowBlock
:::WorkflowBlockItem
In the main navigation, click **Account Management > Roles**.
:::

:::WorkflowBlockItem
Click **+ Add**.
The **Create New Role** window is displayed:

::Image[]{src="https://app.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/StG21t6loLFW7yYagy4hL-20251027-152110.png" size="90" width="1790" height="3390" position="center" alt="Create New Role" darkWidth="1790" darkHeight="3390" showCaption="false"}
:::

:::WorkflowBlockItem
In th&#x65;**&#x20;Name** field, enter a name for the new role.
:::

:::WorkflowBlockItem
In the **Tag** field, select a predefined Tag from the drop-down list.
Tags are used for access control. By assigning a Tag to this role you enable users with this role to access all system object to which the Tag is assigned. If you would like to create a new Tag, see [Creating a Tag](docId\:YpM9tw81ap6nq8sTKv4Rd).
:::

:::WorkflowBlockItem
Under **Permissions**, for object type select the permission level that will be assigned to this role. You can apply the same selection on an entire category (e.g. Resources, Channels, Sources, etc.) by selecting it at the category level, which is highlighted in gray. The options are:

- **Read&#x20;**– allows users with this role to view objects of this type but not edit their configuration.
- **Write** – allows users with this role to edit the configuration of objects of this type.
- **Notify&#x20;**– allows users with this role to receive notifications/alerts regarding this object type. Notify is off by default. Turn it on for every object type this role's users should get alert email about. Without it they get no email, even with Read and Write.
:::

:::WorkflowBlockItem
In the **Users** field, select from the drop-down list the users you would like to assign the role to.
:::

:::WorkflowBlockItem
In the **Groups** field, select from the drop-down list the groups you would like to assign the role to.
:::

::::WorkflowBlockItem
In the **API Keys** field, select one or more API Keys that the permissions for this role should apply to (see [Configuring API Keys](docId\:y5VWL7q34grAoPRjlHzuI) for more detail on how these settings affect API requests).

:::hint{type="info"}
Note that you can edit the Role to add new API Keys, or select the Role when you create a new API Key.
:::
::::

:::WorkflowBlockItem
Click **Save**.
The new role is added to the list of roles.
:::
:::::

