Enterprise plans can define custom roles: start from a built-in role, add or remove specific permissions (per feature, per action), and assign like any role. Use for the real gaps, not for micro-managing.
Building one
Settings → Roles → New → clone the nearest built-in → toggle permissions. Permissions are grouped by feature (agents, sequences, data, integrations, billing) with view/edit/admin levels per group.
Common custom roles
"Deliverability Ops" (mailbox and domain admin, nothing else), "Data Steward" (Golden DB edit + enrichment config, no outbound), "Finance Viewer" (billing + usage reports only), "Agency Seat" (scoped Member minus exports).
Assignment and precedence
Custom roles assign exactly like built-ins and combine with data scoping. A user holds one role per workspace — no stacking; design the role to be complete.
Governance
Role definitions are versioned and logged. Quarterly review: list roles by user count; a custom role with one user is usually a conversation, not a role.