Admin ConsoleUser Management

Member Roles and Permissions

Members of Bitwarden organizations can be granted a variety of roles and levels of permission for collections. You can set roles and collections permissions when you invite users to your organization, or at any time from the Members screen in your organization using the options menu:

Editing member roles
Editing member roles

Member roles

Role determines the what actions a member can take within the context of your organization's available tools. Roles do not determine which collections they have access to.

Options include:

note

Only an owner can create a new owner or assign the owner type to an existing user. For failover purposes, Bitwarden recommends creating multiple owner users.

Custom role

Custom roles are currently available for Enterprise organizations. Selecting the Custom role for a user allows for granular control of permissions on a user-by-user basis. A custom role user can have a configurable selection of administrative capabilities, including:

  • Access event logs

  • Access import/export

  • Access reports

  • Manage account recovery (may also manage device approval requests)

  • Manage all collections (provides the following three options)

    • Create new collections

    • Edit any collection

    • Delete any collection

  • Manage groups

  • Manage SSO

  • Manage policies

  • Manage users

    tip

    Custom users with the Manage users permission can manage other custom users, however they can only assign other custom users the permissions that they themselves have.

  • Manage account recovery

Permissions

Permissions determine what actions a user can take with the items in a particular collection. While role can only set at an individual-member level, permissions can either be set for an individual member or for a group as a whole:

Permissions options
Permissions options
note

The Member access report can be used by Enterprise organizations to see an overview of individual organization member's access to collections, groups, items, and relative permissions.

Suggest changes to this page

How can we improve this page for you?
For technical, billing, and product questions, please contact support