Tenant administrators can define portal-scoped roles and assign the permissions required for a specific customer portal.
Plan the role
- Identify the portal and user group the role serves.
- List the object, record, file, folder, note, email, profile, and configuration actions the users need.
- Start with the minimum required access and add permissions only when the role requires them.
Create and assign the role
- Sign in to https://app.woodsportal.com with role-administration access.
- Open the current role or authorization administration surface.
- Create a role with a clear portal-specific name.
- Select the supported permissions required for the role.
- Save the role.
- Assign it to a safe test user in the intended portal.
- Test both an allowed action and an action that should remain blocked before assigning the role broadly.
Rules and qualification
- Tenant custom roles are portal-scoped.
- Tenant roles cannot receive platform-domain permissions reserved for DigitalWoods operations.
- Role assignment is verified in HubSpot through Manage User Roles and Save Changes. The production custom-role editor location and complete editable permission inventory remain backlogged, so the role-creation path must stay qualified.
- Do not use a broad content permission as a substitute for object-specific data access.
Figure: Assign an existing WoodsPortal role in HubSpot. A screenshot of the custom-role creation and permission editor is still needed.