Controls which side-menu items (and which of their tabs) each role can see and reach — a role with no access to something won't see it in the menu, and can't reach it directly by URL either.
Side menu → Site Admin → Site Settings → the Users tab has a link to Roles & Permissions, or go directly to /site-settings/roles.
The left column lists every role at your site, each with a badge showing how many users currently have it. Click one to load its access settings on the right.
The main checkbox grid is organized by the same categories as the real side menu (Sales and Marketing, Customer Relationship, Project Management, etc.) — check an item to grant that role access to it.
A second grid controls access at the tab level — e.g. a role might be able to open Projects but not see the Vendor Quotes & POs tab on them.
The Administrators role always has full access to everything, and can't be renamed or deactivated. Its checkbox grid is deliberately different — instead of the full menu, it only shows a handful of items:
These are the deliberate exceptions — they need an explicit grant even for Administrators, since they're powerful/sensitive enough that "every admin automatically has this" wasn't the right default.
Click Save. Applies immediately to everyone with that role.
New Role (top of the role list) creates one with no access yet — check the boxes you want, then Save. Rename and Deactivate appear once a non-Administrators role is selected.