Roles grant feature permissions (dot notation, for example pageeditor.read) to human users. Default roles are named Makaira.* and cannot be changed. Custom roles require the Role Manager module, are limited to five per customer, and must be named {customer}.{Name} (The Customer Prefix is added by the UI automatically, but needs to be added when using the API) without -- or __.
API keys use a separate colon permission set. See API Keys and /permissions?type=api.
Related: Role Manager, Users.

