Update Role
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
Changes an existing security role in the current portal. You find the role by name or ID, then change its name, description, role group, status or options. Parameters you leave empty keep their current value.
For how roles are used in Plant an App, see Roles.
Typical Use Cases
- Rename a customer's role when the company name changes
- Approve a role that was created as
PendingorDisabled - Move a role to another role group, or take it out of its group
- Turn a role public or auto-assigned
Don't use it to
- Create a role. Use Create Role instead.
- Give a role to a user or take it away. Use Grant User Role or Revoke User Role instead.
- Clear a role's description. An empty value keeps the current description.
Related Actions
| Action Name | Description |
|---|---|
| Create Role | Creates a role. |
| Delete Role | Deletes a role. |
| Grant User Role | Adds a user to a role. |
| Revoke User Role | Removes a user from a role. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Role Identifier | The role to change, as a role name (for example Editors) or a role ID (for example 42). A number is always treated as an ID. The role must be in the current portal. | Yes | empty string | Yes |
| Role Group Identifier | The role group to move the role to, as a group name or group ID. The group must exist in the portal. Use -1 to take the role out of its group. Leave it empty to keep the current group. | Yes | empty string (no change) | No |
| Role Name | The new name of the role. Leave it empty to keep the current name. | Yes | empty string (no change) | No |
| Role Description | The new description of the role. Leave it empty to keep the current description. | Yes | empty string (no change) | No |
| Role Status | The new status: Pending, Disabled or Approved. In expression mode, use -1 (Pending), 0 (Disabled) or 1 (Approved). Leave it empty to keep the current status. | Yes | empty string (no change) | No |
| Add to existing users | true to also give the role to the users already in the portal. See Considerations. | Yes | false | No |
| Is Public | true to make the role public, so users can subscribe to it themselves from their profile, or false to make it private. Leave it empty to keep the current setting. | Yes | empty string (no change) | No |
| Auto Assign | true to give the role to every user who registers from now on, or false to stop. Because of a product bug, the value of Is Public is used instead. See Considerations. | Yes | empty string (no change) | No |
Output Parameters Reference
This action doesn't produce any output tokens.
Considerations
- There's no permission check in the action. Anyone who can run it can change any role in the portal, including
AdministratorsandRegistered Users. For example, makingAdministratorspublic could let users subscribe to it themselves. Only put it where administrators or other trusted users can reach it, and use a condition to block system roles. - System roles aren't protected. The action lets you rename, disable, regroup or change the options of
AdministratorsandRegistered Users. Don't point it at them. - Empty means "no change". You can't clear a description or name with this action. To take a role out of its group, use
-1inRole Group Identifier. Auto AssignreadsIs Public. Because of a product bug, the action uses the value ofIs PublicforAuto Assign. IfAuto Assignhas any value andIs Publicis empty, the action fails withIncorrect value ... provided for the Auto Assign parameter!. When both have values, auto-assign is set to the value ofIs Public, whatever you put inAuto Assign.Add to existing usersdepends onAuto Assign. The action passes the setting to DNN, and DNN only adds existing users to roles that are auto-assigned.- Boolean values must be
trueorfalse. Values likeyesor1make the action fail withIncorrect value ... provided for the ... parameter!. Case doesn't matter. - Status names are case-sensitive.
Approvedworks,approvedmakes the action fail withUpdate Role : Incorrect value approved provided for the role status!. - New names aren't checked for duplicates. The action doesn't check if another role in the portal already has the name you enter in
Role Name. Check first, for example with a condition or SQL query. - Numeric role names can't be found by name. A value like
2024inRole Identifieris treated as a role ID. - Errors. If
Role Identifieris empty or the role isn't found, the action fails withUpdate Role : No value provided for the role identifier!orUpdate Role : No role was found with the Role Identifier (...)!. A group that isn't found fails withA invalid role group name (...) was provided.orA invalid role group id (...) was provided.Administrators see these messages. Other users see a general error message. - Other role settings aren't available. The security mode, RSVP code, icon and billing settings can't be changed with this action.
Examples
tip
To understand how to use the below examples, please see Running Examples.
1. Approve and rename a customer role
This action finds the role by the ID in [RoleId], renames it after the company, and sets its status to Approved. Everything else stays the same.
{
"Title": "Update Role",
"ActionType": "UpdateRole",
"Description": "Approve and rename the customer role",
"Parameters": {
"RoleIdentifier": "[RoleId]",
"RoleGroupIdentifier": "",
"NewRoleName": "Customer - [CompanyName]",
"RoleDescription": "",
"RoleStatus": "1",
"AddToExistingUsers": "",
"IsPublic": "",
"AutoAssign": ""
}
}
2. Take a role out of its group
This action moves the role named in [RoleName] out of its role group. The condition skips the Administrators and Registered Users roles.
{
"Title": "Update Role",
"ActionType": "UpdateRole",
"Description": "Remove the role from its group",
"Condition": "[RoleName] != \"Administrators\" && [RoleName] != \"Registered Users\"",
"Parameters": {
"RoleIdentifier": "[RoleName]",
"RoleGroupIdentifier": "-1"
}
}
Revised 09/27/2026