# Custom roles

Get answers to all of your questions regarding Brex

**URL Source:** https://www.brex.com/support/custom-roles

---

## Overview

<!-- plans: Premium, Enterprise -->

You can customize our roles for precise access permissions by defining, managing, and assigning exact capabilities to users.  
  
For example, besides our standard account, card, and user management admins, you can create specific role types to assign to finance managers, policy administrators, IT systems administrators, HR managers, or even auditors.

## Creating roles

Account admins and card admins can define, edit, and assign custom roles to grant users access to the features they need.  
  
**Step 1:** Go to _Security _> _Admin roles _> _Create custom role._

![HC - Custom Roles 01](https://brand.brex.com/m/703719aa931518be/webimage-HC-Custom-Roles-01.jpg)

**Step 2: **Add a role name (e.g., “Budget Admin”) and an optional description, and click _Next_.

![HC - Custom Roles 02](https://brand.brex.com/m/121215549789898/webimage-HC-Custom-Roles-02.jpg)

**Step 3: **Choose the role’s capabilities: For help, see Product_ capabilities _below.  
  
**Step 4:** Review your role and click _Next._

![HC - Custom Roles 03](https://brand.brex.com/m/10448a2d301117a7/webimage-HC-Custom-Roles-03.jpg)

### Duplicating roles

Account and card admins can duplicate existing Custom Roles to facilitate user permissions management.



**Step 1:** Go to _Security _> _Admin roles _> Select the existing Role you want to use as a base for duplication by clicking on it to open the side menu.



**Step 2:** Click the three dots at the bottom > _Duplicate & Edit_.



You'll be directed to the same steps as creating a new Role, but with the same permissions already selected as your starting point. From there, you can define the new Role name and modify the capabilities as desired.

## Managing roles

You can make adjustments to an existing custom role by following these steps:  
  
**Step 1: **Go to _Security_ > _Admin roles.  
  
**Step 2:** Click on the custom role you want to edit.  
  
**Step 3: **Click Edit and make your adjustments to the role’s capabilities.  
  
_**Note: **Built-in Brex role types cannot be edited.

## Assigning users to roles

**Step 1: **Go to _Team _and click on the user you want to edit to open the side menu and go to _Roles & Access_.

![HC - Custom Roles 04](https://brand.brex.com/m/375e16e8770fd3c7/webimage-HC-Custom-Roles-04.jpg)

**Step 2:** In the details window, go to _Brex role _and click the text box.  
  
**Step 3: **Select one of the existing roles to change the user's current role.

![HC - Custom Roles 05](https://brand.brex.com/m/6a5a03f128a6605a/webimage-HC-Custom-Roles-05.jpg)

**Note:** The following permissions under _Product access_ can be configured on a user-by-user basis.

- **Bill pay**
   - Draft bills
- **Travel**
   - Book trips
- **Card**
   - Spend on a Brex card

## Product capabilities

Here are product capabilities that can be assigned to a custom role and the effects each one has within the product. 

### Accounts

**<u>Banking</u>**

- View accounts: View statements and transactions.
   - Allows viewing account details, including balance, transaction history, and downloadable statements. Unchecking this option prevents access to all banking information.
- Draft payments: Draft outgoing payments for approval, and deposit checks.
   - This option allows drafting outgoing ACH, wire, and check payments for review and approval and allows check deposits through mobile. Unchecking this option prevents the user from initiating payment drafts or depositing checks. _View accounts is a prerequisite to this capability._
- Manage accounts and payments: Create accounts, update account settings, and initiate and approve external and internal transfers.
   - Allows creating new checking accounts, adjusting existing banking settings, managing payment approval rules, and approving all external money movement. Only users with this permission are able to approve the movement of funds. _View accounts is a prerequisite to this capability._
- Manage invoicing: Create, draft, edit, cancel, and send invoices.
   - Allows full access to the invoicing feature, including creating and sending invoices for payment. Unchecking this option prevents access to invoice management. _View accounts is a prerequisite to this capability._

**<u>Connected accounts</u>**

- View connected accounts: View connected accounts and see their connection status.
   - Allows viewing every account connected to the organization, including each account's connection status. Unchecking this option prevents access to all connected account information.
- Manage connected accounts: Connect, manage, and disconnect accounts.
   - Allows connecting new accounts, updating existing connections, and disconnecting accounts. _View connected accounts is a prerequisite to this capability._

**<u>Credit and reimbursements</u>**

- Manage payments: Make a payment and update autopay settings
   - Allows initiating manual payments and modifying autopay configurations. Unchecking this option prevents the user from managing payment settings or making payments toward the account balance.
- View billing activity
   - View billing activity: Allows viewing account statements, transactions, and payment history. Unchecking this option prevents access to billing activity.

### Accounting

**<u>Accounting settings</u>**

- Manage accounting integration: Setup or edit the organization’s ERP configuration
   - Allows configuring or editing ERP integrations.

**<u>Mappings, fields, and rules</u>**

- Manage mappings, fields, and rules: Create, edit, and delete all accounting mappings, fields, and rules
   - Allows creating, editing, and deleting mappings, fields, and automations. _View mappings, fields, and rules_ is a prerequisite to this capability.

**<u>Prepare and export</u>**

- View transactions: View all accounting transactions
   - Allows viewing all accounting transactions. Unchecking this option prevents access to these transactions.
- Prepare transactions for review: Prepare and send transactions to review
   - Allows preparing and sending transactions for review. _View transactions_ is a prerequisite to this capability.
- Review and export transactions: Review and export transactions to the connected ERP
   - Allows reviewing and exporting transactions to the connected ERP. _View transactions_ is a prerequisite to this capability.
- Unexport transactions: Move exported transactions back to prepare
   - Allows moving exported transactions back to review. _View transactions_ is a prerequisite to this capability.

### Accounts payable

**<u>Bills and vendors</u>**

- View bills and vendors: View all of your organization’s bills and vendors.
   - Allows access to all bills, including those in draft, pending, and paid status, and to all vendors and payments. Unchecking this option removes access to all company bill and vendor details.
- View vendor tax information: View all of your organization’s tax information for vendors.
   - Allows access to view unmasked tax identification numbers (TIN) and W-9 for vendors.
- Manage bills and vendors: View, create, and edit bills and vendors.
   - Allows creating and updating vendors including payment and tax information. Allows drafting and updating bills, including bill payment information. "View bills and vendors" is a prerequisite to this capability.
- Release payments: Finalize and send payments for approved bills.
   - Allows releasing funds for approved payments.

### Reporting

**<u>Reports</u>**

- Manage reports: Create and manage shared reports
   - Allows creating and managing shared reports. _View expenses_ is a prerequisite to this capability.

### Rewards

**<u>Rewards</u>**

- View rewards: View rewards redemption history.
   - Allows viewing a full history of reward redemptions across the organization. Unchecking this option prevents access to reward information.
- Manage rewards: Manage mile transfers to travel loyalty programs
   - Allows transferring points to travel partner loyalty programs and managing referral activities. "View rewards" is a prerequisite to this capability.
- Redeem rewards for cash: Use points for monetary value.
   - Allows redeeming points for direct cashback, statement credits, or gift cards. Unchecking this option prevents monetary reward redemption.
- Redeem rewards for services: Use points for value-added services such as billboards, company-branded swag, private dining and sporting events, and more.
   - Allows redeeming reward points for eligible services.
- Redeem rewards for travel: Use points to book flights and hotels.
   - Allows using rewards to book travel through the Brex travel portal. Unchecking this option prevents access to travel redemption options.

### Security

**<u>Audit trail</u>**

- View audit trail: View all activities across the organization
   - Allows viewing all activities performed in the organization.

### Spend

**<u>Budgets</u>**

- View budgets: View all budgets across the organization
   - Allows the user to view all the organization's budgets. Unchecking this option prevents the user from accessing the organization’s budget information. Users can manage any budgets they own.
- Manage budgets: Create, edit, and delete budgets across the organization
   - Allows creating, editing, and deleting budgets. _View budgets_ is a prerequisite to this capability. Unchecking this option limits the user to viewing budgets only (if _View budgets_ is enabled).

**<u>Cards and limits</u>**

- View cards and limits: View all cards and limits across the organization
   - Allows viewing information about cards and limits across the organization. Unchecking this option prevents access to the organization’s cards and limits. Users can access their own cards and limits in their _Wallet_.
- Manage cards and limits: Create, edit, and delete cards and limits
   - Allows creating, editing, and deleting cards and their limits. _View cards and limits_ is a prerequisite to this capability.

**<u>Policy</u>**

- View policy: View all policy rules across the organization
   - Allows viewing all spending policy rules within the organization.
- Manage policy: Create, edit, and delete policy rules
   - Allows creating, editing, and deleting spending policy rules within the organization. _View policy_ is a prerequisite to this capability.

**<u>Expenses</u>**

- View expenses: View all expenses across the organization
   - Allows the user to view all the organization's expenses. Without this capability, the user cannot access expense reports or view transactions. Users will still have visibility into their expenses and the expenses of their direct reports.
- Manage expenses: Edit, approve, and reject expenses
   - Allows editing, approving, and rejecting expenses. "View expenses" is a prerequisite to this capability. Users will still have visibility into their expenses and the expenses of their direct reports.

### Team

**<u>Organization</u>**

- View organization fields: View all fields and values across the organization
   - Allows viewing all the organization's fields and values. Unchecking this option prevents access to this information.
- Manage organization fields: Create, edit, and delete fields and values
   - Allows creating, editing, and deleting organization fields and values. _View organization fields_ is a prerequisite to this capability.

**<u>Users</u>**

- View users: View all existing and historical users on Brex
   - Allows viewing all existing and historical users in Brex.
- Manage copilots: Set and remove copilots for all users
   - Allows assigning and removing copilots for all users.
- Manage accounting firms: Add and remove accounting firms to the organization for Pro Access
   - Allows configuring and removing accounting firms for Pro Access.
- Invite users: Add and invite users to Brex
   - Allows adding and inviting new users to Brex.
- Update user access: Set a user’s role and ways to spend
   - Allows setting a user's roles and spending permissions.
- Deactivate users: Deactivate and reactivate users
   - Allows deactivating and reactivating users. Without this permission, the administrator cannot change user status.
- Manage users: Set and remove fields on a user
   - Allows creating and removing fields associated with users.

**<u>Entities</u>**

- View entities: View all entities across the organization
   - Allows viewing all the organization's legal entities.
- Manage entities: Create, edit, verify, and delete entities
   - Allows creating, editing, verifying, and deleting legal entities. _View entities_ is a prerequisite to this capability.

**<u>HRIS integrations</u>**

- Manage HRIS connection: Setup or edit the organization’s HRIS configuration
   - Allows configuring or editing connections with HR systems.

### Travel

**<u>Travel</u>**

- View travel: View trips in the organization.
   - Allows viewing all travel bookings and group events across the company. Unchecking this option restricts access to travel booking and group events.
- Manage travel: Manage all the organization's travel.
   - Allows managing travel bookings, managing group events, approving trips, viewing duty of care and access to travel reporting. Unchecking this option limits the ability to manage travel.

## Examples of custom roles

Below are some examples that you can create using this feature. Regularly review the user’s access to ensure alignment with their responsibilities.

### Finance Manager

Ideal for users managing budgets, expenses, and accounting-related tasks. Limit these permissions to key finance personnel to ensure accurate budgeting and compliance.  
  
Permissions:

- View budgets and manage budgets
- View expenses and manage expenses
- View mappings, fields, and rules and manage mappings, fields, and rules
- View transactions, prepare transactions for review, and review transactions for export
- Manage ERP connection

### Policy Administrator

Designed for users responsible for enforcing spending policies. Encourage collaboration with Finance or HR to align policies with organizational goals.  
  
Permissions:

- View and manage policy rules
- View users and update user access

### IT Systems Administrator

Perfect for users managing integrations and technical configurations.  
  
Permissions:

- Manage ERP connection
- Manage HRIS connection
- View audit trail

### HR Manager

Suitable for users overseeing employee roles and organizational fields. Use this role to streamline user management and ensure accurate access control across departments.

Permissions:

- View organization fields and manage organization fields
- View users, Invite users, update user access, and deactivate users
- Manage copilots and manage accounting firms

### Auditor

Designed for users responsible for reviewing financial data and compliance. Assign this role to internal or external auditors for oversight purposes. Ensure permissions are read-only to maintain the integrity of your data.  
  
Permissions:

- View budgets
- View expenses
- View mappings, fields, and rules
- View audit trail

### Procurement Admin

Focused on managing vendors and payables.

Permissions:

- View and manage vendors
- View sensitive vendor information
- View bills and release payments

### Reimbursement Admin

Designed for those managing employee reimbursements and payment approvals.

Permissions:

- View and manage expenses
- Manage payments
- View users and update user access