> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pult.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles

> Who sees which inboxes and records, who runs which actions, and who can reveal sensitive values.

```ts theme={null}
import { role } from "pult"

export const mod = role("mod", {
  label: "Moderator",
  inboxes: [reports, abuse],
  resources: [user, message, repo],
  actions: [message.actions.hide, user.actions.restrict, user.actions.ban],
})

export const support = role("support", {
  inboxes: [support, crashes],
  resources: [user, org],
  actions: [org.actions["*"], user.actions.resetTwoFactor, purgeCache],
  pages: [growth],
  flags: [newEditor],
  reveal: true,
})
```

A role grants:

* `inboxes`: the inboxes its people see, with everything in them.
* `resources`: the resources its people can search, browse and open.
* `actions`: the actions they can run, on records or on their own. `resource.actions["*"]` grants every action on a resource, including ones added later.
* `pages`: the [pages](/build/pages) in their sidebar. Everyone sees home.
* `flags`: the [flags](/build/flags) they can change. Everyone can see flags.
* `reveal`: whether they can reveal [sensitive values](/build/blocks#sensitive-values).
* `status`: whether they can change components and post incidents on the [status page](/build/status).

Roles add up: someone with two roles has everything both grant. Admins of the organization see and can do everything in its projects, and are the only ones who can delete items, manage keys and read the audit log.

## Assigning roles

Invite people from the organization's members settings, then give them roles in the project's settings. Roles themselves only change in code, so who can do what is always in your repository and reviewed like anything else. `pult diff` shows who gains or loses which permission before a deploy, and a granted action that no longer exists in code simply stops working.

## Agents

An agent is an API token with a role, created in the project's settings. It works through the same permissions and leaves the same history as a person. See [Console API](/reference/api).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.