# create_workspace_role

Source: https://modulify.ai/docs/mcp/workspaces/create-workspace-role

Creates a custom role in a workspace with a chosen set of permissions.

- Title: Create a role
- Scope: `workspaces:write`
- Access: Makes changes

Roles are how a workspace gives people less than full access. Every custom role grants `workspace.access` whether you list it or not, and `api.access` is what lets a member use an access token at all, from an MCP client or the [HTTP API](https://modulify.ai/docs/api). [Every permission](https://modulify.ai/docs/reference/members-and-roles#every-permission) explains what each one allows.

Deleting the workspace and managing billing belong to the owner alone, so `workspace.delete` and `billing.manage` are not among the values the tool accepts. A role with no permissions is refused. The answer is the new role, with the `_id` that `assign_member_role` and the `roles` of `invite_workspace_member` take.

It needs the **Manage roles** permission (`roles.manage`) and the workspace on Pro or Enterprise, otherwise it is refused with `You must upgrade to the Pro plan to manage roles!` A workspace holds up to 10 custom roles, and past that the call is refused with `You can create up to 10 roles per workspace!` See [Members and roles](https://modulify.ai/docs/reference/members-and-roles#create-a-custom-role).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `workspaceId` | string | Yes | The workspace id. |
| `name` | string | Yes | What to call the role, 2 to 32 characters. |
| `permissions` | array of strings | Yes | The permissions it grants, at least one of `workspace.access`, `workspace.update`, `members.manage`, `roles.manage`, `projects.delete`, `projects.transfer`, `projects.move`, `projects.domains`, `folders.edit`, `folders.delete`, `folders.move` and `api.access`. |