Roles and access

The built-in Launchpad roles, what each one can do, and how access scopes and opportunity teams narrow or widen what people see.

Launchpad uses the tenant's users, groups and roles. Assign roles in Settings ▸ Users & roles, or in the Orchestrator under Manage access (see Manage access). Both screens change the same tenant roles. Built-in roles# Launchpad permissions cover five areas: opportunities, applications, configuration, analytics and assessments. The roles below are created in every tenant. The tenant Administrator role holds every permission. Role Opportunities Applications Configuration Analytics Assessments Launchpad Administrator view, create, edit, delete view, create, edit, delete view, create, edit, delete view view, create, edit, delete Launchpad Program Manager view, create, edit, delete view, create, edit view view view, edit Launchpad Idea Approver view, edit view — view view, edit Launchpad Business Reviewer view, edit view — view view, edit Launchpad Technical Reviewer view, edit view — view view, edit Launchpad Project Manager view, edit view, create, edit — view view Launchpad Architect view, edit view, create, edit — view view, edit Launchpad Developer view view — — view Launchpad Viewer view view — view view What the areas unlock: Opportunities create: the Submit opportunity button, Register existing automation and Import captured processes. Of the built-in Launchpad roles, only Launchpad Administrator and Launchpad Program Manager have it. To let other employees submit ideas, create a custom role with launchpad_opportunities view and create. Assessments view: the Pipeline page. Assessments edit: the detailed assessment and most review moves. Analytics view: the Portfolio page and the benefit and portfolio sections of Overview. Configuration view/edit: the Settings pages. People pickers need the member listOwner and team pickers list the tenant's users, which needs the users.view permission. Give people who edit opportunities a role that includes it, or the pickers only offer Unassigned. Access scopes# By default a role applies to every opportunity in the tenant. An access scope narrows what a user or group sees to an organization unit or a category (and everything beneath it). Removing the last scope of a user or group gives them the whole tenant again, within their role. Set scopes in Settings ▸ Access scopes. See Settings and administration. Opportunity teams# A person added to an opportunity's Team tab reaches that opportunity even without a Launchpad role. Their role on the team decides whether they can edit it: Business Owner, Process Owner, Project Manager, Business Analyst, Solution Architect, Developer and Tester can edit; Reviewer, Support Owner and Viewer are view only. See Work with opportunities. Next steps# Submit an opportunity Settings and administration

Built-in roles

Access scopes

Opportunity teams

Next steps