Rolling out now. Roles and capabilities are being switched on organization by organization. If yours has not been switched over yet, you will still see the older Admin, Staff and capability checkboxes — that way of working is being retired as the rollout completes.
A person's access comes from the role on their membership — see Roles and capabilities for how roles, levels and inheritance fit together. You can move them onto a different role, and you can adjust individual capabilities for them alone without touching the role itself.
Open the screen
Find the person, open the ··· menu and select Manage user capabilities. The menu is available in three places:
Settings > Users at the top level — the full member list.
The person's profile — one entry per group they belong to.
A group's member list — for their membership in that group.
Memberships are separate. Whatever you change here applies to that one group.
Change the role
Pick the new role from the Role dropdown at the top of the screen.
Select Save.
Switching the role clears any individual adjustments made on this screen — the new role's own capabilities take over.
The dropdown lists the roles your organization has. To add one that is not there yet, see Create a custom role.
Adjust one capability for one person
Open the capability group, then select the row you want to change.
Select Edit. Rows are locked until you do, so nothing changes by accident.
Set the level with the toggles. The levels are cumulative — turning one on turns on everything below it.
Select Save.
A row that no longer matches the role is highlighted, so coming back to this screen shows at a glance what has been changed for this person. Select Revert on a row to put it back to what the role grants — that is all "default" means on this screen, and it is unrelated to the Default label on the roles list.
What an adjustment reaches
An adjustment applies to the one membership you made it on. Unlike the role's own capabilities, it does not flow down into subgroups — granting someone payments access on their Academy membership does not grant it in the teams underneath. When the access has to cover a whole branch, put the person on a role that grants it and attach that role at the top of the branch.
Troubleshooting
Manage user capabilities is not in the menu. You need the Roles capability to see it. It also does not appear for a membership that has been deactivated — reactivate the membership first. If your organization has not been switched over to roles yet, use the older capability checkboxes instead — see Assign capabilities to an admin or staff member.
Save is greyed out. Viewing someone's capabilities needs Read only on Roles; changing them needs Read and write.
The change had no effect. Check you were on the right membership. Access can also arrive from a membership higher up the organization, and that one is unaffected by anything set here — a person with an Admin role in the top-level group keeps it in every group below, whatever you adjust locally.
