Every new organization starts on roles and capabilities. Older organizations are moved over one at a time. Until yours is, you still see the older Admin and Staff capability checkboxes.
A person's access comes from the role on their membership — see Roles and capabilities for how roles, levels and inheritance fit together. You can move them onto a different role, and you can adjust single capabilities for them alone without touching the role itself.
Open the screen
Find the person, open the ··· menu and select Manage user capabilities. The menu is available in three places:
Settings > Users at the top level — the full member list.
The person's profile — one entry per group they belong to.
A group's member list — for their membership in that group.
Memberships are separate. Whatever you change here applies to that one group.
Change the role
Pick the new role under Role.
Select Save.
Switching the role clears any adjustments made for this person on this screen — the new role's own capabilities take over.
The list shows the roles your organization has. To add one that is not there yet, see Create a custom role.
Make someone an Owner. The Owner role is only offered if you are an Owner yourself, and only on a membership in the top-level group. Owner reaches the whole organization, so it cannot be given on a club or a team.
Adjust one capability for one person
Open the card for the capability group.
Select the level next to the capability you want to change, and pick the new one.
Select Save.
A card with changes for this person shows Changed, so coming back to this screen shows at a glance what differs from the role. Reset to the role default inside the card puts all its capabilities back to what the role grants. That is all "default" means on this screen, and it is unrelated to the Default label on the roles list.
On a membership below the top-level group, capabilities marked Organization only in the role editor are not shown, because they would do nothing there.
What an adjustment reaches
An adjustment applies to the one membership you made it on. Unlike the role's own capabilities, it does not flow down into subgroups — granting someone payments access on their Academy membership does not grant it in the teams underneath. When the access has to cover a whole branch, put the person on a role that grants it and attach that role at the top of the branch.
Troubleshooting
Manage user capabilities is not in the menu. You need the Roles capability to see it. It also does not appear for a membership that has been deactivated — reactivate the membership first. If your organization has not been moved over to roles yet, use the older capability checkboxes instead — see Assign capabilities to an admin or staff member.
Save is greyed out. Viewing someone's capabilities needs Roles at View; changing them needs Change.
Owner is not in the list. Only an Owner can give the Owner role, and only on a membership in the top-level group.
The change had no effect. Check you were on the right membership. Access can also come from a membership higher up the organization, and that one is unaffected by anything set here — a person with an Admin role in the top-level group keeps it in every group below, whatever you adjust locally.
