Skip to main content

 

Cisco Meraki Documentation

How to Create and Manage Custom Roles Using RBAC

Learn how to create, review, assign, edit, and delete Custom RBAC roles in the Meraki dashboard for granular admin permissions.

Overview

The Custom Roles feature in the Cisco Meraki dashboard lets you define tailored administrator access levels that align with your organization's needs. Instead of assigning a broad role that grants more access than a job requires, select Read-onlyRead & write, or No access for each resource category. 

Permissions apply across the following product families:

  • Security & SD-WAN (MX WAN appliance)
  • Switching (MS switch)
  • Wireless (MR access point)

Common use cases include:

  • Granting a network engineer full write access to switching but only read access to Security & SD-WAN.
  • Restricting wireless access for contractors or auditors.
  • Creating standardized persona-based roles (for example, Switching Manager role).

This article explains how to create, review, assign, edit, and delete a Custom role using the enhanced Role-Based Access Control (RBAC) interface.

Additive permissions model

 If a user receives multiple roles that affect the same network or product area. The highest level of access granted by any assigned role becomes the user's effective permission. 

For example, if a user receives No access to Wireless in Network X from Role A and Read-only access to Wireless in Network X from Role B, the resulting permission is Read-only access to Wireless in Network X. 

Step-by-step instructions

To use Custom Roles, your organization must first opt in to the new RBAC experience through Early Access. 

Prerequisites 

To use Custom Roles, your organization must first opt in to the new RBAC experience through Early Access. 

  1. In the left navigation menu, go to Organization
  2. Select Early Access
  3. Locate the Role-Based Access Control feature tile. 
  4. Turn on the toggle to enable the beta for the organization. 

After you turn on the toggle, the Roles tab under Organization > Administrators shows the updated Custom roles experience.

Step-by-step instructions

Navigating to the Custom Roles Feature

  1. In the left navigation pane, select Organization > Administrators
  2. Within the Administrators page, switch to the Roles tab. 
  3. The page displays two role groups: 
  • Default roles (Full access, Observer, Switch port manager, SSID Manager, and others.) 
  • Custom roles (roles created by your organization) 

Select + Create Custom role in the upper-right corner too create a new Custom role. 

 

Defining the Custom role name 

The dashboard guides you through a 3-step workflow to create a Custom role. To begin, define the role name: 

  • Enter a descriptive Role name.  
  • Enter an optional Description.  
  • Select Next

Example: 

  • Role name: MX read, MS write 
  • Description: Read-only access to the WAN appliances and full access to switching 

Select Next to proceed.

 

Defining permissions 

Choose the permission level for each product family. Each resource category includes all features under the corresponding dashboard navigation item: 

  • Security & SD-WAN 
  • Switching 
  • Wireless 

Select one of the following permission levels for each resource category: 

  • No access: Unless combined with other roles that grant access to this resource, the user cannot view or manage this product type. 
  • Read only: Unless combined with other roles that grant Read & write access to this resource, the user can view the Monitor and Configure feature groups for this product type, but cannot make changes. 
  • Read & write: Unless combined with other roles that grant Read & write access to this resource, the user can view and make changes to both the Monitor and Configure feature groups for this product type. 

Example configuration: 

  • Security & SD-WAN: Read only 
  • Switching: Read & write 
  • Wireless: No access 

Select Next once the selections reflect your intended permissions.

 

Review and confirm the role

The review step displays: 

  • Role name and description 

  • Permissions selected for each resource category 

Review the information carefully. Use the Edit links next to each section to make adjustments. 

After completing the configuration, select Confirm and add new Custom role

 

 

After confirmation, you will see a success message in the top right corner of the screen, and the newly created role appears under the Custom roles section on the main Roles page. 

 

 

 

Managing Custom roles 

You can edit or delete Custom roles at any time if you meet the required conditions.

Editing a Custom role 

  1. Navigate to Organization Administrators Roles
  2. Scroll to the Custom roles section. 
  3. Select the three-dot (⋯) menu on the role card. 
  4. Select Edit role to reopen the 3-step configuration flow. 

Use this to update permissions or rename the role. 

 

Deleting a Custom role

You can delete only roles that have no admins or Security Assertion Markup Language (SAML) groups assigned. 

 

  1. Open the ⋯ menu for the desired custom role. 
  2. A confirmation dialog will appear. select Delete role to confirm. 
  3. Select Delete role

 

Assigning a Custom role 

After you create Custom roles, assign them to new or existing administrators through the standard admin creation and editing workflow. 

When adding a new admin:

  1. Navigate to Organization > Administrators.
  2. Select Add new admin, or select an existing admin to edit.
  3. In the Role & Scope section, select Assign role.
  4. A side panel opens, displays two tabs:
    • Default - built-in system roles
    • Custom - custom roles created during the beta
  5. Select the Custom tab to view all available custom roles.
  6. Select the radio button for the role you want to assign.
  7. Configure the scope as needed (organization-wide, specific networks, or network tags).
  8. Review and save your changes.

This workflow allows you to assign one or more role-and-scope pairs to the same admin. Assigning multiple role-and-scope pairs supports flexible, layered access aligned with the additive permission model. 

clipboard_e45899c6c4655219b18398c31ffcafcf1.png

 

  • Was this article helpful?