Bulk role assignment — add, replace, or remove
Select several people and change their roles at once in one of three modes. Note: removing roles also requires permission to create them.
Step by step
- Go to Configuration → Team & Access → User Accounts.
- Narrow the list if needed with search or the All roles, All departments, and All statuses filters. You can select only the users you can see.
- Select the checkboxes beside the chosen people. If they are missing, you do not have the required permission; see below.
- A Selected users: N bar appears above the table, with Assign roles and Clear selection buttons. Click Assign roles.
- In Bulk role assignment, choose an Assignment mode: Add to existing, Replace all, or Remove. A sentence below explains what the selected mode does.
- Select the roles the operation should affect.
- Read the Affected users: list — this is your last chance to catch a selection mistake.
- Confirm with the button at the bottom. Its label depends on the mode: Add roles, Replace roles, or Remove roles.
- If a window asks for a 2FA code, enter it (2FA confirmation when changing permissions).
- Check the Roles column for the affected people. If nothing has changed, wait a moment — permission changes can take up to five minutes to apply (“Why can’t they see it?” — diagnosing permissions).
Why the checkboxes appear
The row checkboxes appear only if you have roles permission with both read and create access. If you do not see them, it is a permission issue, not a display bug.
After you select people, the Selected users: N bar appears above the table with the Assign roles action.
Three modes
| Mode | Confirmation button | What it does |
|---|---|---|
| Add to existing | Add roles | Adds selected roles and keeps the existing ones |
| Replace all | Replace roles | Removes all current roles and assigns only those selected |
| Remove | Remove roles | Removes the selected roles and keeps the rest |
Replace all can have painful consequences: a person with three roles who is assigned one role using Replace loses the other two without another prompt. Check the Roles column before using this mode with a large selection.
Removing roles also requires “create” permission
This may seem illogical, so be aware of it in advance: all three modes, including Remove, require roles permission with create access. This is due to the technical way the operation is sent, not the intended permission model. In practice, a role with read and write access but no create access cannot bulk-remove roles.
Only an administrator can assign an administrator role
A role marked as company administrator cannot be assigned by someone who is not an administrator themselves, regardless of how broad their roles permission is (Company administrator and superadministrator — who bypasses what).
Changes are recorded
Every role assignment and removal, individual or bulk, is written to the audit log: who changed what for whom and when.
Before you click
- Make sure Replace all is really what you want.
- Remember that permissions add up and there are no denials: adding a role can only expand access, never narrow it (Role — what it is and how permissions are calculated).
- A permission change can take up to five minutes to apply. Do not worry if the user cannot see the new module immediately (“Why can’t they see it?” — diagnosing permissions).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo