Default Role Templates
The four built-in role presets and what each one grants.
From Settings → Roles → Add from template, you can instantiate any of these four presets at any time. Each one creates an ordinary, editable role; nothing about a template role is special or locked once it's created.
Director / VP
Near-full access to the org — every report, every team — minus billing, API key management, integration configuration and the ability to edit roles themselves. Intended for calibration and org-wide oversight, not day-to-day admin.
Engineering Manager
Own team's reports (Engineer Velocity, Code Review Health, Repo Health, Kanban Flow), My View, the Metrics catalog, team-scoped people visibility, Security Vulnerabilities viewing, the On-Call Registry, plus the ability to manage members. Built for someone running 1:1s and performance reviews for a specific set of direct reports.
Team Lead
Own team's reports (Kanban Flow, Repo Health, Code Review Health), My View, the Metrics catalog, team-scoped people visibility, Security Vulnerabilities viewing, and the On-Call Registry, without member management. For someone who owns team and service health but isn't the people manager.
Engineer
Repo Health and Kanban Flow for their own team, plus My View, team visibility, and Security Vulnerabilities viewing — but deliberately no Engineer Velocity, Metrics, or People directory access, since all three are cross-engineer comparative views in one form or another. My View is this role's only "see your own activity" surface — there's no separate self-view path through People anymore.
My View is granted to all four templates, not just
Engineer — it only ever shows the signed-in user their own data, so
there's no comparison or privacy concern to withhold it for any role.
It's also not gated behind the reports.view permission the way every
actual report is, since it lives in the main sidebar, not the Reports
section.
All four templates grant Security Vulnerabilities viewing, but none grant the ability to edit its remediation SLA — that stays Owner/Admin/Director-only by default (Director gets it as part of its near-full-access grant), same as this page's other org-wide policy settings. Add it to a role explicitly from Settings → Roles if you want a Team Lead or Engineering Manager to manage it too.
These four map directly to the role sections on the marketing site — if you're deciding who to invite as what, that's a good reference for which role fits which job.