The tenant admin role hands someone the keys to everything, and often that's more than you want to give. Maybe a team lead should be able to create spaces, or a security owner should see every space, without becoming a full tenant admin. Tines 3B lets you delegate specific tenant-wide capabilities so people get exactly what they need and nothing more.
Note: Delegating tenant permissions is itself an administrative action:
To assign tenant roles, you need the "Manage roles" permission.
To manage full admins, you need to be able to manage members, which tenant admins can do.
Tenant-wide capabilities come in three levels, from broadest to most specific:
Full tenant admin. Complete access to everything in the tenant. Reserve this for the few people who truly need it.
Built-in creator roles. Ready-made capabilities for creating resources: creating spaces, connectors, skills, networks, groups, or service accounts, plus sharing connectors you create.
Custom tenant roles. Your own bundle of tenant capabilities, such as viewing every space, managing members, viewing audit logs, or managing SSO. Custom roles can hold any tenant permission except full access, which stays exclusive to tenant admins.
Tip: Most delegations should use the built-in creator or custom tenant roles, not full tenant admin.
Delegate through groups with built-in creator roles
Tenant capabilities go to groups, not individuals (except the tenant admin). You can edit them in settings:
Go to settings, then groups, and open the group.
In the tenant roles section, give that group the tenant role and add the people who should have the capability to the group.
Everyone in the group gets the capability, and you manage who has it just by managing group membership. This keeps delegation tidy and easy to audit later.
Bundle capabilities with a custom tenant role
When no single built-in role fits, build a custom one:
Create a custom role for the Tenant scope with the exact permissions you want. See "Create custom roles" for the steps.
Open the group you want to grant it to, go to the Settings tab, and turn on your custom role under Tenant roles.
This is how you delegate capabilities like "view all spaces" or "manage members" to a team without making them tenant admins.
Make someone a full tenant admin
Full tenant admin is handled separately, and it's granted to individual people rather than groups. Go to settings, then groups and open the admins group.
Search for the person and add them.
Tenant admins have full access to everything, so keep the list short. One safeguard to know: a tenant must always have at least one tenant admin, so you can't remove the last one.
Best practices when assigning permissions
A few habits keep tenant access safe:
Grant the narrowest capability that does the job. Prefer a creator or custom role over full tenant admin.
Delegate through groups. It's easier to see and change who has what.
Keep tenant admins few. Every tenant admin can do everything, including changing other people's access.
Revisit periodically. Remove capabilities people no longer need.
