You need permission to manage roles. The Admin role has it.
Go to Settings > Roles and select New role, or edit an existing role.
Under Basic Information, enter a Name and a Description.
Under Permissions, choose a level for each resource:
Manage: create, view, edit and delete all of them.
Contributor (reports only): create new ones, and manage the ones they own or were shared with.
Viewer: view all of them.
None: no access, except to specific dashboards or reports shared with them.
Turn on the Personal tools the role should have, such as Chat or Properties.
Under Data Scope, choose which properties and kinds of data the role sees.
Select Create role or Update role.
[Image: The role form's permissions matrix]
The Admin role is built in and can't be edited. You can't delete a role while users still have it.
Options you don't have yourself are disabled, because you can't grant a permission you lack.