A Role represents a specific set of actions an editor (or an API token) can perform on your administrative area.
"role"
The name of the role
Can change project name and 2FA settings
Can edit favicon, global SEO settings and no-index policy
Can create/edit models and plugins
Can customize content navigation bar
Can create/edit roles and invite/remove collaborators
Can create/delete sandbox environments and promote them to primary environment
Can create/edit webhooks
Specifies the environments the user can access
Can manage Single Sign-On settings
Can access Audit Log
Can create/edit workflows
Can change locales, timezone and UI theme
Can promote environments to primary and manage maintenance mode
Can create/edit Build triggers
Can manage API tokens
Can perform Site Search API calls
Can access the build events log
Allowed actions on a model (or all) for a role
Prohibited actions on a model (or all) for a role
Allowed actions on a model (or all) for a role
Prohibited actions on a model (or all) for a role
Allowed build triggers for a role
Prohibited build triggers for a role
Can create/edit shared filters (both for models and the media area)
The final set of permissions considering also inherited roles
The roles from which this role inherits permissions