Configuring Your Account
Understand Billing
Publishing
Analytics & Reporting
Engagement
AI and Automation
Social Listening
Sprout Integrations
Tagging
Customer Care
Salesforce Service Cloud
Instagram
Facebook
X
Tiktok
Threads
WhatsApp
LinkedIn
YouTube
Pinterest
Bluesky

How do I migrate my legacy roles and permissions to Multi-Role?

Table of Contents

This guide walks Account Owners and Super Admins through migrating from Legacy Roles to Multi-Role (Organizational Roles + Profile Permission Sets). Multi-Role separates what a user can do (Org Role = feature access) from where they can do it (Profile Permission Set = profile/group access), giving you more flexible and scalable permission management.

Who this is for: Advanced plan customers who currently use Legacy Roles and want to transition to Multi-Role.

Permissions required: Manage Permissions

Time estimate: 30 minutes for small teams (< 20 users), 1–2 hours for large teams (50+ users)

Why migrate now? Several newer features — including SCIM provisioning, Dynamic Role Sync, and enhanced JIT SSO — require Multi-Role. If you plan to use automated user provisioning from Okta or Entra ID, you must complete this migration first. Legacy Roles will eventually be discontinued (no date set), but migrating now unlocks capabilities that Legacy Roles cannot access.


Before you begin: Key concepts

Concept

What it means

Legacy Role

Your existing all-in-one roles that bundle feature permissions + profile access together

Organizational Role (Org Role)

Defines what a user can DO — feature access based on job function (e.g., "Social Media Manager," "Care Admin")

Profile Permission Set (PPS)

Defines where a user can DO IT — which Groups and social profiles they can access (e.g., "North America – Full Publishing")

Preset Org Roles

Built-in roles (Super Admin, Social Media Manager, Care Agent, etc.) that you can use immediately or customize

Custom Permissions

Individual per-user permissions without assigning a named role — available if no role template fits

Critical rule: Every user needs BOTH an Org Role AND a Profile Permission Set. You cannot assign just one.


Step 1: Audit your current Legacy Roles

Before converting anything, understand what you have:

  1. Navigate to Account & Settings > Settings > Roles & Team Members.

  2. Click the Roles & Permissions tab.

  3. Review the Legacy Roles section — note each role name and how many users are assigned.

  4. (Optional) Export user permissions (click Export permissions at the top of Team Members) to get a full CSV of who has what.

Create a mapping plan: For each Legacy Role, decide:

  • Which Org Role (preset or custom) should handle the feature permissions?

  • Which Profile Permission Set should handle the profile/group access?

Example mapping:

Legacy Role

→ Org Role

→ Profile Permission Set

"NA Social Manager"

Social Media Manager (preset)

"North America – Full Publishing" (custom PPS)

"EMEA Care Agent"

Care Agent (preset)

"EMEA Profiles – Reply Only" (custom PPS)

"Global Admin"

Super Admin (preset)

N/A (Super Admin includes all access)


Step 2: Create your Multi-Role equivalents using the converter

Sprout provides a built-in converter that auto-populates new roles from your existing Legacy Roles:

Convert to Organizational Role:

  1. On the Roles & Permissions tab, find the Legacy Role you want to convert.

  2. Click the pencil icon next to the Legacy Role.

  3. Follow the prompts and click Convert to Custom Organizational Role.

  4. The new Org Role is pre-populated with the company/feature permissions from your Legacy Role.

  5. Review and adjust permissions as needed (this is a good time to clean up over-permissioned roles).

  6. Click Create new Role.

Convert to Profile Permission Set:

  1. Click the pencil icon on the same (or different) Legacy Role.

  2. Follow the prompts and click Convert to Profile Permission Set.

  3. The new PPS is pre-populated with the group/profile access from your Legacy Role.

  4. Review and adjust profile access as needed.

  5. Click Save.

Tip: One Legacy Role typically converts into BOTH an Org Role AND a PPS, since Legacy Roles bundle both permission types. Convert the same Legacy Role twice — once for the Org Role, once for the PPS.

Or use Preset Org Roles:

If your Legacy Role maps closely to a standard job function, skip the converter and use a Preset Org Role instead:

  • Super Admin — Full administrative access

  • Social Media Manager — Publishing, reporting, listening, and content management

  • Care Admin — Case management, inbox, and team oversight

  • Care Agent — Reply, case handling, and inbox access

  • Analyst — Reporting and listening (read-only for most features)

Presets can be customized after assignment if they're close but not exact.


Step 3: Assign users to their new Multi-Roles

Once your Org Roles and Profile Permission Sets are created:

  1. Navigate to the Team Members tab.

  2. Click a user to edit their role assignment.

  3. Assign their new Organizational Role (from the Org Roles dropdown).

  4. Assign their new Profile Permission Set (from the PPS dropdown).

  5. Click Save.

For bulk assignment:

  • Use Bulk User Permissions (export CSV → update role columns → re-import) to migrate many users at once.

  • Each row in the CSV now has columns for Legacy Role, Organizational Role, and Profile Permission Set.

Important: Users can have BOTH a Legacy Role and Multi-Role simultaneously during migration. This is expected — it lets you migrate gradually without disrupting anyone's access. The most permissive combination applies.


Step 4: Verify the migration

Before removing Legacy Roles, confirm everything works:

Use the Customer Audit Trail:

  • Export audit logs to track all role changes during migration and spot errors.

Pilot group testing:

  • Start with one team (e.g., your newest team or highest-turnover department).

  • Have them confirm they can still access everything they need.

  • Check that they CAN'T access anything they shouldn't.

Post-migration spot checks:

  • Ask team leads to verify their team's permissions match expectations.

  • Test key workflows: Can Care agents still reply? Can publishers still post? Can analysts still export reports?

Export permissions again:

  • Run a fresh permissions export and compare it against your pre-migration export to confirm equivalent access.


Step 5: Remove Legacy Role assignments

Once you've confirmed the Multi-Role assignments are correct:

  1. Navigate to each user (or use bulk editing).

  2. Remove their Legacy Role assignment.

  3. Confirm they retain access through their Org Role + PPS combination.

Note: You cannot delete a Legacy Role while users are still assigned to it. Remove all user assignments first, then delete the Legacy Role from the Roles & Permissions tab if desired.


Step 6: Clean up and maintain

  • Delete unused Legacy Roles — Once fully migrated, remove Legacy Roles to avoid confusion.

  • Schedule quarterly reviews — Permissions drift over time. Review role assignments with team leads regularly.

  • Use Preset Roles for new hires — Onboard new users with Presets for speed, customizing only when needed.

  • Consider SCIM or DRS — Now that you're on Multi-Role, you can enable automated provisioning. → SCIM Setup Guide | Dynamic Role Sync


Important constraints

Constraint

What it means for you

One Org Role + one PPS per user

A user cannot have two Org Roles or two Profile Permission Sets. If someone needs permissions from two roles, create a custom role that combines them.

Super Admin stays as-is

Super Admin is not a Multi-Role Org Role — it remains a separate assignment with full access. You don't need to "migrate" Super Admins.

Legacy Roles can coexist temporarily

During migration, users can have both a Legacy Role and Multi-Role. The most permissive combination applies.

SCIM/DRS override manual changes

If you later enable SCIM or Dynamic Role Sync, role assignments are managed from your IdP. Changes made manually in Sprout will be overwritten at next sync.

New customers can't create Legacy Roles

Only existing customers who had Legacy Roles before Multi-Role's launch (December 2024) still have them. This is a one-way migration.


Features that require Multi-Role

Feature

What it does

Legacy Role support?

SCIM Provisioning (Okta/Entra ID)

Auto-provision and deprovision users from your IdP

❌ Multi-Role only

Dynamic Role Sync

Auto-update user roles based on IdP group changes at each SSO login

❌ Multi-Role only

JIT SSO Provisioning

Auto-provision first-time SSO users with default roles

⚠️ Works with Legacy but Multi-Role recommended

Bulk User Invite CSV

Import users with role assignments via CSV

✅ Both supported

Export Permissions

Audit all user permissions

✅ Both supported


Naming best practices

Type

Recommended naming

Example

Org Roles

Job-function-based names

"Social Media Manager," "Care Admin," "Content Strategist"

Profile Permission Sets

Scope-based names (region, product, access level)

"North America – Full Publishing," "EMEA – Read Only," "All Profiles – Reply Only"

Avoid: Naming PPS after job titles (they change) or combining function + scope in one name (defeats the purpose of separation).


FAQ

Can I migrate one team at a time?
Yes — this is the recommended approach. Start with a pilot team, verify, then expand. Users on Legacy Roles and users on Multi-Role can coexist indefinitely.

Will migrating disrupt my team's access?
No. You add Multi-Role assignments BEFORE removing Legacy Roles. During the overlap period, the most permissive combination applies. Users experience no interruption.

Do users need to log out and back in?
No. Role changes take effect immediately — no logout/login required.

What if I need to undo the migration?
Re-assign the Legacy Role to the user. Legacy Roles still work — they're just no longer the recommended path. You can revert at any time.

Is this available on Standard or Professional plans?
No. Roles (both Legacy and Multi-Role) are an Advanced plan feature. Standard and Professional customers use Groups & Social Profiles with individual user permissions instead.

How long does migration typically take?

  • < 20 users: 30 minutes

  • 20–50 users: 1 hour

  • 50–200 users: 1–2 hours (use bulk CSV)

  • 200+ users: Contact your CSM or ProServ consultant for assisted migration





Screenshot 2024-11-19 at 3.29.30 PM.png





Screenshot 2024-11-19 at 3.30.26 PM.png

Was this article helpful?

0 out of 0 found this helpful

Table of Contents