Standard roles
Following are the standard IC web roles. These are fully independent and do not need to be "stacked." Whenever users with stacked roles are spotted, the lesser roles should be removed to reduce the length of the users page.
- Reader
Readers have the ability to view unpublished content. - Contributor
Contributors should have all permissions allowing entity creation/editing as well as deletion of their own material, except in cases where the entity is strictly administrative in nature (e.g. users). All edits should automatically generate revisions! - Editor
This role has all of the permissions of contributors plus the additional power to delete entities as well as powers that straddle the line between contributor and managers/administrator, e.g. editing taxonomies. - Manager
This role contains all permissions except highly technical and set it/forget it sorts of things like caching. - Administrator
Administrators receive all permissions.
Add-on roles
Add-on roles are need-specific. A typical example from some sites is "Webform," which contains roles specific to Webform administration. Add-on roles should be narrow—constrained to a single permission or group of related permissions—and should be named to clearly indicate at a glance what permissions they confer. Add-on roles can (and should) stack.