---
title: "OKR module advanced permissions"
canonical: "https://support.appfire.com/space/SPM/1918767695/OKR%20module%20advanced%20permissions"
format: markdown
---
> Macro (aura-html)

## Configure the advanced setup

> Macro (excerpt-include)

  

> ⚠️ OKR advanced permissions are **global**—any changes you introduce also change the organization's settings.

> ℹ️ If a user is granted an Admin role in the OKR module, they will retain full admin access, even if they have another role assigned or are an OKR Owner, as long as they hold the Admin role.

![Screenshot of the Advanced setup for permissions in the OKR module.](media://400caca5-e7f9-441c-9f8a-c5063d96d7f3)

### Global roles

These roles serve as the foundation for your role setup. Global roles apply to all OKRs.

By default, there are two roles: 

- **Admin** (role granting with full privileges)
- **Viewer** (role allowing only to view OKRs).

#### Default global role

The default role is set to Admin, but you can change this setting and assign the Viewer or a custom role to be the default one.

1. Click the **triple dots** (**…**) next to the role and select **Edit**.
2. Check the **Set as a default role** option.

![Setting a default global role.](media://b5de93dc-e253-4a31-98ba-6a35eb2dba00)

#### Custom global role

You can also create custom global roles and assign only very specific actions users are allowed to perform, such as deleting or commenting on OKR updates.

1. Click the **+Add a custom role** button.
2. **Name** the new role
3. Add users/teams to this role (now or later).
4. Optionally: Set the new role as the default one.

![Create new role screen on the permissions advanced setup page in the OKR module.](media://8b5ce21b-3b27-46d0-bffb-c992cf7bd69e)

Once a new global role is added, it will appear in the **Permissions** section, where you can select which permissions to include in the role.

### OKR ownership-based roles

These roles are important additions to the global roles that support the OKR process within the organization. When a global role is assigned, OKR Owners, Collaborators, or Team members are granted additional permissions to the OKRs to which they or their team is assigned.

For example, if the viewer role is set as the default and the OKR ownership-based roles are activated, only those actively involved in an OKR (they own and/or collaborate on the OKR) are granted additional permissions related to that OKR. Other users will only be able to view the OKRs.

![OKR ownership-based roles section of the OKR module's advanced permissions page.](media://e6d392b7-4754-473c-ad1d-599b8196f0e7)

You can choose which roles to keep by toggling them on or off, and decide which permissions belong to each role. The **Permissions** section on this page lets you configure these settings.

## Customize permissions for individual roles

Check the permissions you want to assign to individual roles, including OKR ownership-based and custom roles. Changes in the **Permissions **section are saved automatically and applied instantly.

> ℹ️ Permissions of the **Admin** and **Viewer** roles cannot be customized. You can only assign users and groups to them or set them to default roles.

![OKR advanced permissions. Some permissions are selected for individual roles.](media://0e9e3323-e121-4a61-b415-b516e49c35d3)