Vibe OnCall ships with three built-in roles — Admin, Member, and Read Only — and for most teams those are enough. When they aren't, a custom role grants exactly the permissions you pick: a support engineer who can declare and comment on incidents but never page anyone, an ops engineer who manages integrations without becoming a full admin. For the built-in roles themselves and how organization and team roles stack, see Roles and permissions.
Go to Settings → Administration → Roles. The page lists every role in your organization — the three built-in ones, marked with a Built-in role badge and not editable, plus any custom roles you've created — with the number of permissions each grants and how many people hold it.
You need the Admin role to create, edit, or delete roles.

The permissions you select decide what the role can change; the two View toggles decide what it can see. A new role starts with both on the narrower setting, so widen them if the role should see everything a Member does. Team roles still apply on top, so a team admin still manages their own team.

| Group | Permission | What it allows |
|---|---|---|
| Incidents | View incidents ① | Always on. The toggle beside it decides which incidents the rest of the group applies to |
| Create incidents | Declare a new incident | |
| Update incidents | Change incident details such as severity and status | |
| Acknowledge incidents | Acknowledge an incident to indicate it is being handled | |
| Resolve incidents | Mark an incident as resolved | |
| Create war rooms | Open a war room channel for an incident | |
| Page responders | Send a page to responders | |
| Send incident emails | Send email updates to stakeholders | |
| Comment on incidents | Post comments on an incident timeline | |
| Alerts | View alerts ② | Always on. The toggle beside it decides which alerts the rest of the group applies to |
| Update alerts | Change alert details such as severity, owner, and labels | |
| Acknowledge alerts | Acknowledge an alert to indicate it is being handled | |
| Page from alerts | Page a team or person from an alert | |
| Note on alerts | Add, edit, and delete notes on an alert | |
| Run alert actions | Run a configured action from an alert | |
| Routing | Manage routing in Global and every team ③ | Create, edit, and delete routing attributes and notification conditions |
| Integrations | Manage integrations in Global and every team ③ | Connect, reconfigure, and disconnect integrations |
| Members | Manage members ④ | Invite members, revoke their access, and assign roles. Importing members also needs ⑤ |
| Teams | Manage every team ③ | Create, edit, and delete teams, and manage their members. Importing teams also needs ⑤ |
| API Keys | Manage API keys | Create and revoke the organization's API keys |
| PagerDuty & Opsgenie | Import from PagerDuty and Opsgenie ⑤ | Preview and import schedules, escalation policies, members, and teams from your connected PagerDuty or Opsgenie account |
① View incidents is a toggle, not a checkbox. Involved limits the incident permissions to incidents the person or their team responds to, created, or is a stakeholder on; All incidents applies them to every incident in the organization.
An incident can also reach someone through its service, which takes two things: