<h2>Base system roles</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="reference" /><meta name="DC.title" content="Base system roles" /><meta name="abstract" content="Administrators can assign one or more base system user roles to grant access to base system platform features and applications." /><meta name="description" content="Administrators can assign one or more base system user roles to grant access to base system platform features and applications." /><meta name="DC.subject" content="Roles, base system roles" /><meta name="keywords" content="Roles, base system roles" /><meta name="DC.relation" scheme="URI" content="../../../administer/roles/concept/ua-creating-roles.html" /><meta name="DC.relation" scheme="URI" content="../../../administer/general/concept/intro-now-platform-landing.html" /><meta name="DC.relation" scheme="URI" content="../../../administer/general/concept/config-now-platform-core-features.html" /><meta name="DC.relation" scheme="URI" content="../../../administer/roles/reference/r_SpecialAdministrativeRoles.html" /><meta name="DC.relation" scheme="URI" content="../../../administer/user-administration/concept/c_ReadOnlyRole.html" /><meta name="DC.relation" scheme="URI" content="../../../administer/roles/reference/application-specific-roles.html" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2023-08-03" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="r_BaseSystemRoles" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Base system roles</title></head><body id="r_BaseSystemRoles"> <div class="breadcrumb"><a class="link" href="../../../administer/general/concept/intro-now-platform-landing.html" title="As a platform administrator, you have the power of the Now Platform at your fingertips. The Now Platform is an application platform as a service that automates business processes across the enterprise.">Administer the Now Platform</a> > <a class="link" href="../../../administer/general/concept/config-now-platform-core-features.html" title="The Now Platform provides for a multitude of customization options to your applications. Customize your UI, handle user and data administration, and localize your instance for time zones, currencies, and more.">Configure Now Platform Core Features</a> > </div> <h1 class="title topictitle1" id="ariaid-title1">Base system roles</h1> <div class="body refbody"><p class="shortdesc">Administrators can assign one or more base system user roles to grant access to base system platform features and applications.</p> <div class="section" id="r_BaseSystemRoles__section_d5t_mpy_tzb"> <p class="p">To learn more about managing per-user subscriptions, see <a class="xref" href="../../subscription-management/concept/managing-user-subscriptions-v2.html">../../subscription-management/concept/managing-user-subscriptions-v2.html</a> and contact your account representative.</p> </div> <div class="section" id="r_BaseSystemRoles__admin"><h2 class="title sectiontitle">Administrator [admin]</h2> <p class="p">The administrator role. This role has access to all system features, functions, and data because administrators can override access control list (ACL) rules and pass all role checks. Avoid assigning this role to your users when more targeted roles are available.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"> <ul class="ul" id="r_BaseSystemRoles__ul_tnw_d1v_gdc"><li class="li">ais_admin</li><li class="li">announcement_admin</li><li class="li">catalog</li><li class="li">catalog_admin</li><li class="li">catalog_builder_editor</li><li class="li">catalog_lookup_admin</li><li class="li">catalog_template_editor</li><li class="li">chat_admin</li><li class="li">evam_admin</li><li class="li">image_admin</li><li class="li">import_admin</li><li class="li">import_scheduler</li><li class="li">import_set_loader</li><li class="li">import_transformer</li><li class="li">live_feed_admin</li><li class="li">ml_admin</li><li class="li">ml_labeler</li><li class="li">nlu_admin</li><li class="li">nlu_editor</li><li class="li">nlu_user</li><li class="li">pa_data_collector</li><li class="li">pa_viewer</li><li class="li">personalize_dictionary</li><li class="li">platform_ml_create</li><li class="li">platform_ml_read</li><li class="li">platform_ml_write</li><li class="li">search_application_admin</li><li class="li">search_relevancy_model_admin</li><li class="li">sn_ace.ace_user</li><li class="li">sn_employee.admin</li><li class="li">sn_hr_sp.admin</li><li class="li">sn_hr_sp.esc_admin</li><li class="li">sn_nlu_workbench.nlu_feedback_admin</li><li class="li">sn_templated_snip.template_snippet_admin</li><li class="li">sn_templated_snip.template_snippet_reader</li><li class="li">sn_templated_snip.template_snippet_writer</li><li class="li">sp_admin</li><li class="li">taxonomy_admin</li><li class="li">user_criteria_admin</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Grant this privilege carefully. If you have sensitive information, such as HR records, that you must protect, create a custom admin role for that area. Train any users authorized to see those records to act as the administrator. Also note the <a class="xref" href="r_SpecialAdministrativeRoles.html" title="Certain roles grant specific administrative rights without the full privileges of the admin role. For example, an administrator can grant a user the right to change UI policy but not client scripts.">Special Administrative Roles</a>.<div class="note"><span class="notetitle">Note:</span> Users with roles related to the Key Management Framework can only be modified by admins with the kmf_admin role. For details on KMF roles, see <a class="xref" href="../administer/key-management-framework/reference/kmf-roles.html" target="_blank" rel="noopener noreferrer">Key Management Framework roles</a>.</div> </dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__agent_admin"><h2 class="title sectiontitle">Agent administrator [agent_admin]</h2> <p class="p">Agent administrators can download and administer the built-in system agent. They can manage MID Server-related scripts.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_ef1_k1z_yxb"><li class="li">agent_security_admin</li><li class="li">view_changer</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__ais_admin"><h2 class="title sectiontitle">AI search administrator [ais_admin]</h2> <p class="p">AI search administrators can query, create, update, and delete indexing and search settings and log messages through the <a class="xref" href="../../ai-search/concept/overview-ais.html" title="The ServiceNow AI Search application provides a consumer-grade search engine for ServiceNow Service Portal, ServiceNow Now Mobile, and ServiceNow Virtual Agent . Intelligent query features help you quickly find the answers you need."><span class="ph">AI Search</span></a> application.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__app_client_company_installer"><h2 class="title sectiontitle">Application client company installer [app_client_company_installer]</h2> <p class="p">Users assigned the app_client_company_installer role can install applications containing the same company as the currently logged in instance. Assigning this role enables first-time installation of applications for the company associated with the current instance. Users with this role can’t install an application for another company.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__app_client_user"><h2 class="title sectiontitle">Application client user [app_client_user]</h2> <p class="p">Application client users can install applications containing the same company as the currently logged in instance.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__approval_admin"><h2 class="title sectiontitle">Approval administrator [approval_admin]</h2> <p class="p">Approval administrators can view or modify approval requests not directly assigned to them. Use the approver_user role to enable approvers to view or modify only requests directly assigned to them.</p> <p class="p">Fulfillers may approve within the product to which they are subscribed (ITSM Fulfiller approving within ITSM). This approval may be in the platform or via email. No additional entitlement is required.</p> <p class="p">Fulfillers may not approve beyond the product to which they are subscribed (ITSM Fulfiller approving within Procurement, GRC, etc.). This approval would need an additional approval entitlement for the user.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__approver_user"><h2 class="title sectiontitle">Approver users [approver_user]</h2> <p class="p">Approver users can modify requests for approval routed to them. They also have all the capabilities of requesters.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">There’s a fee associated with this role. Don’t assign it to users without confirming your organization has the appropriate entitlement.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__asset"><h2 class="title sectiontitle">Asset user [asset]</h2> <p class="p">Asset users can manage hardware and software assets.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_kyq_wbz_yxb"><li class="li">inventory_user</li><li class="li">cmdb_query_builder</li><li class="li">canvas_user</li><li class="li">financial_mgmt_user</li><li class="li">cmdb_read</li><li class="li">contract_manager</li><li class="li">category_manager</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__assignment_rule_admin"><h2 class="title sectiontitle">Assignment rule administrator [assignment_rule_admin]</h2> <p class="p">Assignment rule administrators can manage assignment rules.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__business_process_admin"><h2 class="title sectiontitle">Business process administrator [business_process_admin]</h2> <p class="p">Business process admins can create, read, update, and delete all records and their relationships in the business process.</p> <p class="p">In the context of Governance, Risk, and Compliance (GRC), users with the sn_grc.admin role who manage GRC applications and their setup automatically gain access to this role. This access enables the GRC administrators to administer a business process and its records similar to other GRC tables.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: business_process_manager</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">This role is assigned to users who are administrators and have thorough information and training on business processes. Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__business_process_manager"><h2 class="title sectiontitle">Business process manager [business_process_manager]</h2> <p class="p">Business process managers can create, read, and update any business process and manage the relationship of business processes with other records. This role is assigned to business process managers who are usually specialists and manage multiple business processes in the organization. Assign this role to users who generally work with other employees and are experts around business processes.</p> <p class="p">In the context of GRC, users with the sn_grc.manager role automatically inherit this role that enables them to manage the business processes for the entire organization.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: business_process_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__business_process_user"><h2 class="title sectiontitle">Business process user [business_process_user]</h2> <p class="p">Business process users can update the business processes that a user owns and can also read any business process. This role must be assigned to the respective process owners who manage the business process that they own. This role can also be provided to users who are required to view the business processes in the organization and understand them better.</p> <p class="p">In the context of GRC, users with the sn_risk.user role are automatically assigned this role. This role enables users to manage the business processes that they own as well as read all business processes.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_read</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__catalog_admin"><h2 class="title sectiontitle">Catalog administrator [catalog_admin]</h2> <p class="p">Catalog administrators can manage the Service Catalog application, including catalog categories and items.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_p2k_mfz_yxb"><li class="li">user_criteria_admin</li><li class="li">catalog_builder_editor</li><li class="li">catalog_template_editor</li><li class="li">catalog</li><li class="li">catalog_lookup_admin</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__catalog_editor"><h2 class="title sectiontitle">Catalog editor [catalog_editor]</h2> <p class="p">Catalog editors can create, modify, and publish items within categories that they’re assigned to.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__catalog_item_designer"><h2 class="title sectiontitle">Catalog item designer [catalog_item_designer]</h2> <p class="p">Catalog item designers can view the status of their category requests. This role is granted automatically to users when they make a request for an item designer category.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__catalog_manager"><h2 class="title sectiontitle">Catalog manager [catalog_manager]</h2> <p class="p">Catalog managers can view and assign catalog editors to their categories. Can also create, modify, and publish items within their categories.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__catalog"><h2 class="title sectiontitle">Catalog user [catalog]</h2> <p class="p">Catalog users have read and some write access to all Service Catalog Requests, Tasks, and Items.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_z4h_cfz_yxb"><li class="li">Catalog Request Approvers > $1000</li><li class="li">Catalog Request Approvers for Sales</li><li class="li">Field Services</li></ul> </dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__category_manager"><h2 class="title sectiontitle">Category manager [category_manager]</h2> <p class="p">Category managers can create, edit, and delete model categories.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: model_manager</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__sn_cmdb_admin"><h2 class="title sectiontitle">CMDB administrator [sn_cmdb_admin]</h2> <p class="p">CMDB administrators can access all CMDB data, tools, and UIs. Users with this role can set policies such as class manager, app service requirement, that an editor can’t.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_vhc_2p3_1yb"><li class="li">canvas_admin</li><li class="li">cmdb_ms_admin</li><li class="li">data_manager_admin</li><li class="li">sn_cmdb_editor</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__cmdb_dedup_admin"><h2 class="title sectiontitle">CMDB de-duplication administrator [cmdb_dedup_admin]</h2> <p class="p">CMDB de-duplication admins can review and remediate CMDB de-duplication tasks.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_read</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__sn_cmdb_editor"><h2 class="title sectiontitle">CMDB editor [sn_cmdb_editor]</h2> <p class="p">CMDB editors can create, edit, and delete CMDB records but can't change policies such as data manager, class manager.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_r1r_np3_1yb"><li class="li">cmdb_ms_editor</li><li class="li">sn_cmdb_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__cmdb_ms_admin"><h2 class="title sectiontitle">CMDB multi-source administrator [cmdb_ms_admin]</h2>Can create and run a query, and can modify CMDB 360 properties. Contains cmdb_ms_write role.<dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_ms_editor</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__cmdb_ms_editor"><h2 class="title sectiontitle">CMDB multi-source editor [cmdb_ms_editor]</h2> <p class="p">CMDB multi-source editors can create and query, read, and write CMDB records, but can't perform recompute action.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_ms_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__cmdb_ms_user"><h2 class="title sectiontitle">CMDB multi-source user [cmdb_ms_user]</h2> <p class="p">CMDB multi-source users have read and execute access to the multi-source queries.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_read</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__cmdb_read"><h2 class="title sectiontitle">CMDB reader [cmdb_read]</h2> <p class="p">CMDB reader users can read data from the CMDB hierarchy.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__sn_cmdb_user"><h2 class="title sectiontitle">CMDB user [sn_cmdb_user]</h2> <p class="p">CMDB users have read-only access to CMDB data and basic UI.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_ypz_zp3_1yb"><li class="li">app_service_user</li><li class="li">canvas_user</li><li class="li">cmdb_ms_user</li><li class="li">cmcb_query_builder</li><li class="li">data_manager_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__contract_manager"><h2 class="title sectiontitle">Contract manager [contract_manager]</h2> <p class="p">Contract managers can create, edit, and delete contracts through the Contract Management application.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_qyn_j3z_yxb"><li class="li">canvas_user</li><li class="li">financial_mgmt_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__unlimited_createnow"><h2 class="title sectiontitle">CreateNow unlimited [unlimited_createnow]</h2> <p class="p">Role for CreateNow unlimited licensed users.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__data_classification_admin"><h2 class="title sectiontitle">Data classification administrator [data_classification_admin]</h2> <p class="p">Data classification administrators manage all aspects of the Data Classification application, data classification code setup, and assignment.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: data_classification_auditor</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__data_classification_auditor"><h2 class="title sectiontitle">Data classification auditor [data_classification_auditor]</h2> <p class="p">Data classification auditors audit Data Classification code assignments.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__ecmdb_admin"><h2 class="title sectiontitle">Enterprise CMDB administrator [ecmdb_admin]</h2> <p class="p">Enterprise CMDB administrators can perform administrative tasks and access tables and records in Enterprise CMDB.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: cmdb_read</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__filter_admin"><h2 class="title sectiontitle">Filter administrator [filter_admin]</h2> <p class="p">Filter administrators can create, edit, and delete filter [sys_filter] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_xxl_tqh_1yb"><li class="li">filter_global</li><li class="li">filter_group</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__filter_group"><h2 class="title sectiontitle">Filter group user [filter_group]</h2> <p class="p">Filter group users can create filters that belong to groups of which the user is a member.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__gauge_maker"><h2 class="title sectiontitle">Gauge maker [gauge_maker]</h2> <p class="p">Gauge makers can create gauges from reports. Starting with <span class="ph">Helsinki</span>, reports are no longer made into gauges.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__filter_global"><h2 class="title sectiontitle">Global filter user [filter_global]</h2> <p class="p">Global filter users can create global filter [sys_filter] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__template_editor_global"><h2 class="title sectiontitle">Global template editor [template_editor_global]</h2> <p class="p">Users with the template_editor_global role can create templates for global use.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__template_editor_group"><h2 class="title sectiontitle">Group template editor [template_editor_group]</h2> <p class="p">Users with the template_editor_group role can create templates for groups.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__guided_tour_admin"><h2 class="title sectiontitle">Guided tour administrator [guided_tour_admin]</h2> <p class="p">Guided tour administrators can create, modify, and delete guided tour [sys_embedded_tour_guide] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: sn_tourbuilder.tour_admin</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__image_admin"><h2 class="title sectiontitle">Image administrator [image_admin]</h2> <p class="p">Image administrators can create, modify, and delete image [db_image] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__impersonator"><h2 class="title sectiontitle">Impersonator [impersonator]</h2> <div class="p">Impersonators can impersonate users.<div class="note warning"><span class="warningtitle">Warning:</span> This role doesn’t enable the impersonation of admin users.</div> </div> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">For details on impersonation, see <a class="xref" href="../../users-and-groups/concept/c_ImpersonateAUser.html" title="Administrators can impersonate other authenticated users for testing purposes and view impersonation logs.">Impersonate a user</a>.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__import_admin"><h2 class="title sectiontitle">Import administrator [import_admin]</h2> <p class="p">Import administrators can manage all aspects of import set [sys_import_set] records and imports.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_lnq_xzh_1yb"><li class="li">import_set_loader</li><li class="li">import_transformer</li><li class="li">import_scheduler</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__import_scheduler"><h2 class="title sectiontitle">Import scheduler [import_scheduler]</h2> <p class="p">Import schedulers can schedule imports.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd"><div class="note warning"><span class="warningtitle">Warning:</span> Grant this role carefully. The import_scheduler can execute scripts with administrator level privileges.</div> </dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__import_set_loader"><h2 class="title sectiontitle">Import set loader [import_set_loader]</h2> <p class="p">Import set loader users can load import set [sys_import_set] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__import_transformer"><h2 class="title sectiontitle">Import transformer [import_transformer]</h2> <p class="p">Import transformer users can manage import set transform map [sys_transform_map] records and run transforms.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__inventory_admin"><h2 class="title sectiontitle">Inventory administrator [inventory_admin]</h2> <p class="p">Inventory administrators administer stockrooms, stock models, stock rules.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_qjj_dc3_1yb"><li class="li">inventory_user</li><li class="li">canvas_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__inventory_user"><h2 class="title sectiontitle">Inventory user [inventory_user]</h2> <p class="p">Inventory users have access to stock information.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__itil"><h2 class="title sectiontitle">ITIL [itil]</h2> <p class="p">ITIL users can open, update, close incidents, problems, changes, and configuration management items. This role is the base system technician role. Users with the itil role can have tasks assigned to them.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_ecy_sc3_1yb"><li class="li">dependency_views</li><li class="li">agent_workspace_user</li><li class="li">sn_incident_write</li><li class="li">sn_sow.sow_user</li><li class="li">snc_platform_rest_api_access</li><li class="li">cmdb_query_builder</li><li class="li">sn_cmdb_editor</li><li class="li">sn_problem_write</li><li class="li">tracked_file_reader</li><li class="li">sn_request_write</li><li class="li">view_changer</li><li class="li">viz_creator</li><li class="li">template_editor</li><li class="li">cmdb_read</li><li class="li">app_service_user certification</li><li class="li">sn_change_write</li><li class="li">sn_sttrm_condition_read</li><li class="li">email_composer</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_fcy_sc3_1yb"><li class="li">Field Services</li><li class="li">Catalog Request Approvers > $1000</li><li class="li">Catalog Request Approvers for Sales</li></ul> </dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__itil_admin"><h2 class="title sectiontitle">ITIL administrator [itil_admin]</h2> <p class="p">ITIL administrators can delete incidents, problems, changes, and other related records. This role is intended for team leads.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_rss_nd3_1yb"><li class="li">sn_cmdb_admin</li><li class="li">assessment_admin</li><li class="li">sn_bm_client.benchmark_data_viewer</li><li class="li">cmdb_read</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting admin roles when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__knowledge"><h2 class="title sectiontitle">Knowledge [knowledge]</h2> <p class="p">Knowledge users can write, edit, and review knowledge management articles.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__knowledge_admin"><h2 class="title sectiontitle">Knowledge administrator [knowledge_admin]</h2> <p class="p">Knowledge administrators can manage knowledge bases.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: knowledge</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__list_updater"><h2 class="title sectiontitle">List updater [list_updater]</h2> <p class="p">List updater users can select the <span class="ph uicontrol">Update Entire List</span> and <span class="ph uicontrol">Update Selected</span> menu options on a list.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__maint"><h2 class="title sectiontitle">Maintenance [maint]</h2> <p class="p">This role is reserved for <span class="ph">ServiceNow</span> use.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">This role can’t be assigned or impersonated, and is reserved for <span class="ph">ServiceNow</span> use.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__mid_server"><h2 class="title sectiontitle">MID server [mid_server]</h2> <p class="p">MID server users can access to the tables that MID servers ordinarily use. This role should be granted to your MID servers.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: soap</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">This role should be assigned to user accounts created for MID servers to interact with your instance. For details, see <a class="xref" href="../product/mid-server/task/t_SetupMIDServerRole.html" target="_blank" rel="noopener noreferrer">Create the MID Server user and grant the role</a>.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__model_manager"><h2 class="title sectiontitle">Model manager [model_manager]</h2> <p class="p">Model managers can create, modify, and delete base model [cmdb_model] records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: catalog_editor</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__nobody"><h2 class="title sectiontitle">Nobody [nobody]</h2> <p class="p">The nobody role means that nobody has access, not even admin, or maint users.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd"><div class="dangertitle">Danger</div><div class="note danger">Applying the nobody role may be irreversible if applied to important system functions.</div> </dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize"><h2 class="title sectiontitle">Personalize [personalize]</h2> <p class="p">Users with the personalize role can personalize forms, lists, rules, controls, and scripts.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_lpc_lh3_1yb"><li class="li">personalize_control</li><li class="li">personalize_rules</li><li class="li">personalize_dictionary</li><li class="li">personalize_choices</li><li class="li">personalize_styles</li><li class="li">personalize_responses</li><li class="li">personalize_list</li><li class="li">personalize_form</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_choices"><h2 class="title sectiontitle"><span class="ph">Personalize choices</span> [personalize_choices]</h2> <p class="p">Users assigned to the personalize_choices role can personalize the choices for a list field.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_control"><h2 class="title sectiontitle">Personalize control [personalize_control]</h2> <p class="p">Personalize control users can personalize controls on lists, such as filters, links, and buttons.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_dictionary"><h2 class="title sectiontitle">Personalize dictionary [personalize_dictionary]</h2> <p class="p">Users with the personalize_dictionary role can personalize dictionary entries and labels.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_form"><h2 class="title sectiontitle">Personalize form [personalize_form]</h2> <p class="p">Users with the personalize_form role can personalize forms.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_list"><h2 class="title sectiontitle">Personalize list [personalize_list]</h2> <p class="p">Users with the personalize_list role can personalize lists.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_responses"><h2 class="title sectiontitle">Personalize responses [personalize_responses]</h2> <p class="p">Users with the personalize_form role can personalize predefined responses for suggestion fields, such as the additional comments field.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_rules"><h2 class="title sectiontitle">Personalize rules [personalize_rules]</h2> <p class="p">Personalize rules users can personalize business rules and scripts. This role contains additional roles for granting selective, administrative access to rules and scripts.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_ot1_d33_1yb"><li class="li">ui_action_admin</li><li class="li">business_rule_admin</li><li class="li">client_script_admin</li><li class="li">ui_policy_admin</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting this role to users who don’t need access to all the roles contained in this role.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_styles"><h2 class="title sectiontitle">Personalize styles [personalize_styles]</h2> <p class="p">Users with the personalize_styles role can personalize field styles.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__personalize_ui"><h2 class="title sectiontitle">Personalize UI [personalize_ui]</h2> <p class="p">Users with the personalize_ui role can personalize forms and lists.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_vs4_2k3_1yb"><li class="li">personalize_form</li><li class="li">personalize_list</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__section_qxl_c1w_qzb"><h2 class="title sectiontitle">Platform Rest API access [snc_platform_rest_api_access]</h2> <div class="p">Allows access to Platform Rest APIs. This role is contained with in the ITIL [itil] role.<ul class="ul" id="r_BaseSystemRoles__ul_fbm_g1w_qzb"><li class="li">Table API</li><li class="li">Import Set API</li><li class="li">Aggregate API</li><li class="li">Attachment API</li></ul> </div> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__public"><h2 class="title sectiontitle">Public [public]</h2> <p class="p">No login is required to access features or functions with the public role.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__release_admin"><h2 class="title sectiontitle"><span class="ph">Release administrator</span> [release_admin]</h2> <p class="p">Release administrators can edit the release history for a release.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_admin"><h2 class="title sectiontitle">Report administrator [report_admin]</h2> <p class="p">Report administrators can manage, share, publish, and schedule all reports. Users assigned this role can access the <span class="ph menucascade"><span class="ph uicontrol">Reports</span> > <span class="ph uicontrol">Administration</span></span> module and manage all report-related objects. The report_admin role inherits all other report roles.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_jsq_1l3_1yb"><li class="li">gauge_maker</li><li class="li">report_alias_admin</li><li class="li">report_global</li><li class="li">report_group</li><li class="li">report_publisher</li><li class="li">report_scheduler</li><li class="li">viz_admin</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_alias_admin"><h2 class="title sectiontitle">Report alias administrator [report_alias_admin]</h2> <p class="p">Report alias administrators can maintain field and value aliases.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_global"><h2 class="title sectiontitle">Report global [report_global]</h2> <p class="p">Report global users can manage reports that are shared with everyone (listed in Global).</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: report_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_group"><h2 class="title sectiontitle">Report group [report_group]</h2> <p class="p">Report group users can manage and share reports that are shared with them (listed in Group).</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: report_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_publisher"><h2 class="title sectiontitle">Report publisher [report_publisher]</h2> <p class="p">Report publisher users can publish reports any that they can manage. Publishing a report creates a public link to that report. Users with this role must also have another role that grants permission to create, edit, and share reports.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: report_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_scheduler"><h2 class="title sectiontitle">Report scheduler [report_scheduler]</h2> <p class="p">Report scheduler users can schedule emailing of all reports that they can see, including reports they can’t manage. Users with this role must also have another role that grants permission to create, edit, and share reports.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: report_user</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__report_user"><h2 class="title sectiontitle">Report user [report_user]</h2> <p class="p">Report users can create and view reports that have been shared with them. Users with this role can't share, edit, or delete reports that have been shared with them.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: viz_creator</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__script_fix_admin"><h2 class="title sectiontitle">Script fix administrator [script_fix_admin]</h2> <p class="p">Script fix administrators can manage fix scripts.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__search_application_admin"><h2 class="title sectiontitle">Search application administrator [search_application_admin]</h2> <div class="p">Search application administrators can insert, update, and delete search user experience-related configuration tables:<ul class="ul" id="r_BaseSystemRoles__ul_npm_243_1yb"><li class="li">sys_search_context_config</li><li class="li">sys_search_source</li><li class="li">m2m_search_context_config_search_source</li><li class="li">sys_search_facet</li><li class="li">sys_search_filter</li></ul> Search application admin is granted the ais_admin role to enable AI search configuration.</div> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_l4y_yn3_1yb"><li class="li">ais_admin</li><li class="li">personalize_dictionary</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap"><h2 class="title sectiontitle"><span class="ph">SOAP</span> [soap]</h2> <p class="p">users with the soap role can query, create, update, and delete records on all tables, as well as execute scripts.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_ttk_mq3_1yb"><li class="li">soap_create</li><li class="li">soap_delete</li><li class="li">soap_ecc</li><li class="li">soap_query</li><li class="li">soap_script</li><li class="li">soap_update</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_create"><h2 class="title sectiontitle"><span class="ph">SOAP create</span> [soap_create]</h2> <p class="p">Users with the soap_create role can create records in all tables and columns.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_delete"><h2 class="title sectiontitle"><span class="ph">SOAP delete</span> [soap_delete]</h2> <p class="p">Users with the soap_delete role can delete records in all tables and columns.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_ecc"><h2 class="title sectiontitle"><span class="ph">SOAP ECC</span> [soap_ecc]</h2> <p class="p">Users with the soap_ecc role can query, create, and update on the ECC Queue table only.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_query"><h2 class="title sectiontitle"><span class="ph">SOAP query</span> [soap_query]</h2> <p class="p">Users with the soap_query role can query records on all tables and columns.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_query_update"><h2 class="title sectiontitle"><span class="ph">SOAP query update</span> [soap_query_update]</h2> <p class="p">Users with the soap_query_update role can query and update all tables and columns.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_wp3_fr3_1yb"><li class="li">soap_query</li><li class="li">soap_update</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_script"><h2 class="title sectiontitle"><span class="ph">SOAP script</span> [soap_script]</h2> <p class="p">Users with the soap_script role can execute business rule endpoint functions via <span class="ph uicontrol">script.do</span>.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__soap_update"><h2 class="title sectiontitle"><span class="ph">SOAP update</span> [soap_update]</h2> <p class="p">Users with the soap_update role can update records on all tables and columns.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__survey_admin"><h2 class="title sectiontitle">Survey administrator [survey_admin]</h2> <p class="p">Survey administrators can see all surveys, their definitions, question, instances created by them and others. Users with this role can use all modules in the <span class="ph uicontrol">Survey</span> application menu.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_rsq_pr3_1yb"><li class="li">assessment_admin</li><li class="li">sn_bm_client.benchmark_data_viewer</li><li class="li">sn_publications_recipients_list_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__survey_creator"><h2 class="title sectiontitle">Survey creator [survey_creator]</h2> <p class="p">Survey creators can manage survey definitions, questions, and instances created by them.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_vt3_xr3_1yb"><li class="li">sn_bm_client.benchmark_data_viewer</li><li class="li">sn_publications_recipients_list_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default: Survey Creators</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__survey_reader"><h2 class="title sectiontitle">Survey reader [survey_reader]</h2> <p class="p">Survey readers can view surveys and related information, such as survey responses, survey groups, scorecards, and reports. Users with this role can't change or modify surveys or survey responses.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role: sn_bm_client.benchmark_data_viewer</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__task_editor"><h2 class="title sectiontitle">Task editor [task_editor]</h2> <p class="p">Task editors can edit protected task fields.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__template_editor"><h2 class="title sectiontitle">Template editor [template_editor]</h2> <p class="p">Template editors can create templates for personal use, and modify or delete personal templates. This role is included in the itil role in the base system.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__template_scheduler"><h2 class="title sectiontitle">Template scheduler [template_scheduler]</h2> <p class="p">Template schedulers can schedule template-based record creation.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__text_search_admin"><h2 class="title sectiontitle">Text search administrator [text_search_admin]</h2> <p class="p">Text search administrators can customize Global Text Search groups and tables.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__timecard_admin"><h2 class="title sectiontitle">Timecard administrator [timecard_admin]</h2> <p class="p">Timecard administrators can access all timecard records.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_a2p_vt3_1yb"><li class="li">timecard_approver</li><li class="li">timecard_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__timecard_approver"><h2 class="title sectiontitle">Timecard approver [timecard_approver]</h2> <p class="p">Timecard approvers approve or reject time cards for users.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_mjy_253_1yb"><li class="li">pa_viewer</li><li class="li">timecard_user</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__timecard_user"><h2 class="title sectiontitle">Timecard user [timecard_user]</h2> <p class="p">Timecard users can create time cards themselves, and view their own time cards.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__user"><h2 class="title sectiontitle">User [user]</h2> <p class="p">The user role has no functionality and doesn’t grant access to any assets on your instance. Users with this role are counted as licensed fulfillers.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__user_admin"><h2 class="title sectiontitle">User administrator [user_admin]</h2> <p class="p">User administrators can administer users, groups, locations, skills, and companies.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_gjd_zv3_1yb"><li class="li">fsm_skill_admin</li><li class="li">skill_admin</li><li class="li">territory_admin</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__view_changer"><h2 class="title sectiontitle">View changer [view_changer]</h2> <p class="p">View changers can switch active views.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__workflow_admin"><h2 class="title sectiontitle">Workflow administrator [workflow_admin]</h2> <p class="p">Workflow administrators can create, edit, publish, or delete graphical workflows.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand"><ul class="ul" id="r_BaseSystemRoles__ul_h4m_qw3_1yb"><li class="li">activity_creator</li><li class="li">itom_admin</li><li class="li">workflow_creator</li><li class="li">workflow_publisher</li></ul> </dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__workflow_creator"><h2 class="title sectiontitle">Workflow creator [workflow_creator]</h2> <p class="p">Workflow creators can create graphical workflows.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__workflow_publisher"><h2 class="title sectiontitle">Workflow publisher [workflow_publisher]</h2> <p class="p">Workflow creators can publish graphical workflows.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__workflow_report_viewer"><h2 class="title sectiontitle">Workflow report viewer [workflow_report_viewer]</h2> <p class="p">Workflow report viewers can access the workflow scratchpad for reports.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">None</dd> </dl> </div> <div class="section" id="r_BaseSystemRoles__ts_admin"><h2 class="title sectiontitle">Zing text search administrator [ts_admin]</h2> <p class="p">Users with the ts_admin role can administer the <a class="xref" href="../../search-administration/concept/c_ZingTextSearch.html" title="Index and search record data by table.">Zing text indexing and search engine</a>.</p> <dl class="dl"> <dt class="dt dlterm">Contains Roles</dt> <dd class="dd">List of roles contained within the role.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Groups</dt> <dd class="dd">List of groups this role is assigned to by default.</dd> <dd class="dd ddexpand">None</dd> <dt class="dt dlterm">Elevated</dt> <dd class="dd">Whether the role is an elevated role. Elevated roles aren’t assigned to users or groups, and must be used by elevation. For details, see <a class="xref" href="../administer/security/concept/c_ElevatedPrivilege.html" target="_blank" rel="noopener noreferrer">Elevated privilege roles</a>.</dd> <dd class="dd ddexpand">No</dd> <dt class="dt dlterm">Special considerations</dt> <dd class="dd">Avoid granting an admin role when more specialized roles are available.</dd> </dl> </div> </div> <div class="related-links"> <ul class="ullinks"><li class="link ulchildlink"><strong><a href="../../../administer/roles/reference/r_SpecialAdministrativeRoles.html">Special administrative roles</a></strong><br /> Certain roles grant specific administrative rights without the full privileges of the admin role. For example, an administrator can grant a user the right to change UI policy but not client scripts.</li><li class="link ulchildlink"><strong><a href="../../../administer/user-administration/concept/c_ReadOnlyRole.html">Read-only role</a></strong><br /> The read-only role (snc_read_only) restricts a user or a group of users to read-only access on the tables to which the user already has access.</li><li class="link ulchildlink"><strong><a href="../../../administer/roles/reference/application-specific-roles.html">Application specific roles</a></strong><br /> Applications you install on your instance may include additional roles. Follow the links in this section to see roles installed along with applications.</li></ul> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="../../../administer/roles/concept/ua-creating-roles.html" title="Admins can create and configure roles that grant specific permissions, which govern what users and groups with that role can do.">Creating roles</a></div> </div> </div></body></html></div>