How to Create and Manage Custom Roles Using RBAC
Overview
The Custom Roles feature in the Cisco Meraki dashboard lets you define tailored administrator access levels that align with your organization's needs. Instead of assigning a broad role that grants more access than a job requires, select Read-only, Read & write, or No access for each resource category.
Permissions apply across the following product families:
- Security & SD-WAN (MX WAN appliance)
- Switching (MS switch)
- Wireless (MR access point)
Common use cases include:
- Granting a network engineer full write access to switching but only read access to Security & SD-WAN.
- Restricting wireless access for contractors or auditors.
- Creating standardized persona-based roles (for example, Switching Manager role).
This article explains how to create, review, assign, edit, and delete a Custom role using the enhanced Role-Based Access Control (RBAC) interface.
Additive permissions model
If a user receives multiple roles that affect the same network or product area. The highest level of access granted by any assigned role becomes the user's effective permission.
For example, if a user receives No access to Wireless in Network X from Role A and Read-only access to Wireless in Network X from Role B, the resulting permission is Read-only access to Wireless in Network X.
Step-by-step instructions
To use Custom Roles, your organization must first opt in to the new RBAC experience through Early Access.
Prerequisites
To use Custom Roles, your organization must first opt in to the new RBAC experience through Early Access.
- In the left navigation menu, go to Organization.
- Select Early Access.
- Locate the Role-Based Access Control feature tile.
- Turn on the toggle to enable the beta for the organization.
After you turn on the toggle, the Roles tab under Organization > Administrators shows the updated Custom roles experience.
Step-by-step instructions
Navigating to the Custom Roles Feature
- In the left navigation pane, select Organization > Administrators.
- Within the Administrators page, switch to the Roles tab.
- The page displays two role groups:
- Default roles (Full access, Observer, Switch port manager, SSID Manager, and others.)
- Custom roles (roles created by your organization)
Select + Create Custom role in the upper-right corner too create a new Custom role.
Defining the Custom role name
The dashboard guides you through a 3-step workflow to create a Custom role. To begin, define the role name:
- Enter a descriptive Role name.
- Enter an optional Description.
- Select Next.
Example:
- Role name: MX read, MS write
- Description: Read-only access to the WAN appliances and full access to switching
Select Next to proceed.
Defining permissions
Choose the permission level for each product family. Each resource category includes all features under the corresponding dashboard navigation item:
- Security & SD-WAN
- Switching
- Wireless
Select one of the following permission levels for each resource category:
- No access: Unless combined with other roles that grant access to this resource, the user cannot view or manage this product type.
- Read only: Unless combined with other roles that grant Read & write access to this resource, the user can view the Monitor and Configure feature groups for this product type, but cannot make changes.
- Read & write: Unless combined with other roles that grant Read & write access to this resource, the user can view and make changes to both the Monitor and Configure feature groups for this product type.
Example configuration:
- Security & SD-WAN: Read only
- Switching: Read & write
- Wireless: No access
Select Next once the selections reflect your intended permissions.
Review and confirm the role
The review step displays:
-
Role name and description
- Permissions selected for each resource category
Review the information carefully. Use the Edit links next to each section to make adjustments.
After completing the configuration, select Confirm and add new Custom role.
After confirmation, you will see a success message in the top right corner of the screen, and the newly created role appears under the Custom roles section on the main Roles page.
Managing Custom roles
You can edit or delete Custom roles at any time if you meet the required conditions.
Editing a Custom role
- Navigate to Organization > Administrators > Roles.
- Scroll to the Custom roles section.
- Select the three-dot (⋯) menu on the role card.
- Select Edit role to reopen the 3-step configuration flow.
Use this to update permissions or rename the role.
Deleting a Custom role
You can delete only roles that have no admins or Security Assertion Markup Language (SAML) groups assigned.
- Open the ⋯ menu for the desired custom role.
- A confirmation dialog will appear. select Delete role to confirm.
- Select Delete role.
Assigning a Custom role
After you create Custom roles, assign them to new or existing administrators through the standard admin creation and editing workflow.
When adding a new admin:
- Navigate to Organization > Administrators.
- Select Add new admin, or select an existing admin to edit.
- In the Role & Scope section, select Assign role.
- A side panel opens, displays two tabs:
- Default - built-in system roles
- Custom - custom roles created during the beta
- Select the Custom tab to view all available custom roles.
- Select the radio button for the role you want to assign.
- Configure the scope as needed (organization-wide, specific networks, or network tags).
- Review and save your changes.
This workflow allows you to assign one or more role-and-scope pairs to the same admin. Assigning multiple role-and-scope pairs supports flexible, layered access aligned with the additive permission model.


