> ## Documentation Index
> Fetch the complete documentation index at: https://docs.y.uno/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles

> Use default roles or build custom ones to control what each team member can do

A **role** is a set of permissions. The **Roles** tab shows what each role can do and is where you create your own.

Open it from **Organization → Roles**.

## Default roles

Yuno ships six default roles:

| Role | Description |
| :- | :- |
| Admin | Access to all features in the dashboard. |
| Agent | View and take actions on payments. |
| Developer | View and take actions on integrations and webhooks. |
| Read only | View all features in the dashboard. |
| Custodian | Assign this role when you invite Yuno team experts to join your team. |
| IAM Admin | Manage access and security settings such as SSO and roles. |

## Role scope: account or organization

The same role behaves differently depending on the level it is granted at:

* **Account** — the role applies only on the accounts the person is assigned to. Invite them separately for each account they need.
* **Organization** — the role applies across every account in the organization, including accounts created later. This works for any role, not just Admin. An organization-level "payment analyst" sees payments everywhere without being invited account by account.

<Note>
  **Security permissions are organization-level only**

  Permissions under **Security**, such as configuring SSO, can only be granted through an organization-level role. They cannot be assigned on a single account.
</Note>

## Creating a custom role

Select **Create role**, then set a name, a description, and the permissions the role should carry.

### Per-environment permissions

Each permission is configured independently for:

* **Sandbox** — testing and development.
* **Production** — live operations and sensitive data.

So a role can have full access in Sandbox for testing while staying restricted in Production.

### Available permissions

* **Insights** — access to actionable payment insights
* **Payments** — view and operate payments, manage payment links
* **Payouts** — view payouts and transaction details
* **Reconciliation** — view settlement reports
* **Connections** — view and manage payment connections
* **Routing** — view and manage processing routes
* **Checkout builder** — view and build checkout configurations
* **Developers** — view and manage account keys
* **Webhooks** — view and manage webhooks
* **Accounts** — manage account settings
* **Team and roles** — view and manage team members and roles
* **Risk conditions** — view and manage rules and lists
* **Audit logs** — view dashboard, API, and monitor logs

## Related docs

* [Team members](/docs/using-yuno/organization/team-members): granting a role to a person.
* [Audit logs](/docs/using-yuno/settings/audit-logs): reviewing who changed what.
