A role is a named set of permissions, assigned to team members to control what they can see and do. Meridian ships three default roles, and anyone with the Roles: Edit permission can create custom roles.
The owner sits above the role system and always passes every permission check. The owner is not a role. See Team members for how ownership works.
Default roles
Custom roles
Anyone with Roles: Edit can create custom roles with any combination of permissions from the catalog. A non-owner can’t grant a permission they don’t hold themselves, which prevents privilege escalation. Ownership transfer and organization deletion are not permissions, so no role can include them. A custom role can be scoped to specific apps, so a member reaches only the apps that role covers. A single role can be assigned to many team members; editing a role changes access for everyone who has it.
The permission model
Permissions come in two categories:
- Organization permissions apply across the whole organization regardless of app scoping: the organization itself, team members and roles, applications, billing, audit logs, demo mode and the data export.
- App permissions apply within a specific app, and honour a role’s app scope: integrations, credentials, App Store listing, Shopify API alerts, Plan Builder, Hosting, dev databases, database backups, Emails, Automations, CRM, Logbook and Affiliates.
The owner always retains ownership transfer and organization deletion, no matter how roles are configured, and can’t be removed or locked out of anything. Everything else, billing included, is a permission that admins hold and that a custom role can be given. For the full list of permissions, see Permissions. Last modified on September 28, 2026