Custom roles
Bitrise ships with built-in system roles at both the workspace and project level, but no two teams organize access the same way. A custom role lets you name a role, describe what it's for, choose where it applies, and pick exactly the permissions it grants.
Unlike built-in system roles, custom roles can be edited or removed at any time, and they're assigned the same way as any built-in system role: to a person directly, or to a workspace group.
Custom roles are available on the Enterprise plan. The UI is available today. API, CLI, and MCP access for creating and modifying custom roles programmatically isn't available yet; it's planned for a later phased release.
Where custom roles applyClick to copy link
Every custom role picks one of two scopes when it's created:
- Workspace: billing, members, workspace settings, security. See Roles and permissions in workspaces for the built-in Workspace-level roles.
- Bitrise CI: apps, builds, workflows, secrets, build approvals. See Roles and permissions for Bitrise CI for the built-in project-level roles.
Workspace and Bitrise CI aren't levels of one hierarchy: each is its own scope with its own built-in roles. Custom roles aren't a third scope, they let you build additional roles within one of these two.
A Bitrise CI-scoped custom role applies only to the specific project(s) you assign it to, the same way built-in project roles like Admin or Developer work today, not to every Bitrise CI project in the workspace at once. Custom roles don't extend into other Bitrise products with their own access model, like Release Management.
Permissions from every role you hold, built-in or custom, combine together. There's no way to use one role to explicitly block or override a permission granted by another.
Creating and assigning a roleClick to copy link
A workspace Owner or Manager can create, edit, and remove custom roles. Once a role exists, you assign it the same way as any other role: to a person directly, or to a workspace group.
Creating, editing, and removing a custom role, and reassigning it, are all logged today as part of the workspace's audit trail.