# Creating roles & assigning permissions

A role bundles permissions that apply across the whole organisation — such as managing
members or creating projects. Every member holds exactly one role.

## Create a role

1. Open the **Roles and permissions** section in **Management**.
2. Use **New role** to add a title and – optionally – a description.
3. Enable the permissions you want, grouped by topic: accounts, projects, tickets,
   users, and assistant.

## Set a default role

Mark one role as the **default role**. Every newly invited member automatically receives
it, so you don't have to assign permissions person by person.

## Assign a role

Change a member's role in the **Members** section: open the row and pick a different role.
The administrator role always has full access and cannot be edited or deleted. A role that
still has members assigned to it cannot be deleted either.

<div class="docs-callout docs-callout--warning">
  <div class="docs-callout__title">Project permissions take precedence</div>
  <p>Permissions granted directly on a project override the ones from the role.</p>
</div>

For how to fine-tune access on a per-project basis, see
[Controlling access per project](https://lalabase.com/docs/en/guides/team/project-access).
