> For the complete documentation index, see [llms.txt](https://docs.request.biz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.request.biz/administrator-guide/security/roles.md).

# Roles

The **Roles** section gives the ability to create new roles, configure them and assign them to users. It consists of two sections; the left-hand side shows the **Roles** view while the right-hand side shows various tab pages to configure the role selected in the view on the left-hand side.

The *Administrator* role is a standard role in the <code class="expression">space.vars.PRODUCT\_NAME</code> system and is always shown. Permissions, options, and templates of the Administrator role cannot be modified. You can however, assign members to this role. By default this role is automatically linked to the admin user.

Roles with **Is default** checked are assigned automatically for newly registered users, also via Active Directory.

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FefGwqJCLg8clnkoK5jv9%2Fimage.png?alt=media&amp;token=460772f2-b79f-4747-8b09-801d11e12848" alt="" width="563"><figcaption></figcaption></figure></div>

## Edit Role <a href="#edit_role" id="edit_role"></a>

There are five tabs available to configure a role: Permissions, Options, Templates, Members, and External Groups (as defined in your Active Directory system).

### **Permissions**

The **Permissions** tab provides the ability to set permissions for the available resource types. Currently the following resource types are supported:

* Requests
* Tasks

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FOSCCOuYY38aOvtgwVit9%2Fimage.png?alt=media&amp;token=3fc75b3c-753e-4c7d-8292-2e6d02af3b84" alt="" width="563"><figcaption></figcaption></figure></div>

The toolbar at the top has an **Open** command, allowing to change permissions for a specific  resource type:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FXbiY5FfhuBekxcsm6edu%2Fimage.png?alt=media&amp;token=09407d79-dcca-4cfb-bae7-71b893b28ac6" alt="" width="303"><figcaption></figcaption></figure></div>

### **Options**

The **Options** tab provides the ability to set specific options for a role. At the moment of writing, there is only one option available, named **Co-administrator**. It allows a non-admin user to access the <code class="expression">space.vars.ADMIN\_FRONTEND\_NAME</code>.

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2F5pnaOJQZgx41OFHHUJXh%2Fimage.png?alt=media&amp;token=4d4a2231-361b-4c2b-82c6-34e1b81d6daf" alt="" width="563"><figcaption></figcaption></figure></div>

### **Templates**

The **Templates** tab provides the ability to select which templates a role has access to:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FZcrfAGpetxwlfUhL1Oac%2Fimage.png?alt=media&amp;token=59d00002-9399-46bc-9108-cb50ffb92ff2" alt="" width="563"><figcaption></figcaption></figure></div>

Using the **Manage Templates** button in the toolbar allows granting or revoking access to templates for a specific role:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2F6eJTo1zf4eiu7T0ecHxZ%2Fimage.png?alt=media&amp;token=cb11f973-f248-4210-8c94-1b40bdf26718" alt="" width="563"><figcaption></figcaption></figure></div>

The shown dialog shows two lists:

1. Available templates - these are templates that are not assigned to the role yet,
2. Selected templates - these are templates that have been assigned to the role.

You can move templates between both lists and then press the **Save** button when done.&#x20;

### **Members**

The **Members** tab allows adding and/or removing users to/from the selected role:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FMpjrErcRATQTXPuXpFwQ%2Fimage.png?alt=media&amp;token=9b842695-aa34-432b-b1b0-63bbf338cab9" alt="" width="563"><figcaption></figcaption></figure></div>

Clicking the **Manage Members** button in the toolbar opens the following dialog:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2Fsj0IJ65aln5eTJPKbgJQ%2Fimage.png?alt=media&amp;token=a2155cc3-998a-4ec3-bfd4-ea89b2d6348d" alt="" width="563"><figcaption></figcaption></figure></div>

This dialog works the same as the **Manage Templates** dialog described above.

### **External Groups (Optional)**

This tab is optional and depends on the **User Role Management** setting in the [External Authentication](/administrator-guide/security/settings.md#external-authentication) group of the [**Security > Settings**](/administrator-guide/security/settings.md) section. When this setting is set to the value `Automatically synchronize ... groups with roles on user login` the **External Groups** tab will become available:&#x20;

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FfhEJ4T8dSOmG2ifRnBa3%2Fimage.png?alt=media&amp;token=7b494016-d9cb-46aa-bc38-527ead50ff16" alt="" width="563"><figcaption></figcaption></figure></div>

This tab allows mapping groups defined in your Active Directory system (i.e. [Entra Microsoft ID](/administrator-guide/security/settings/microsoft-entra-id-meid.md) or [Active Directory Federation Services](/administrator-guide/security/settings/active-directory-federation-services-adfs.md)) to <code class="expression">space.vars.PRODUCT\_NAME</code> roles.

#### Adding Groups

The **Add Groups** command allows defining a new group or select an already existing group. To define a new group, the name of the group needs to be typed in the **Group Name** field and pressing the <kbd>Enter</kbd> key.&#x20;

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2Fkkkdi1bXSuhWYZttBMuC%2Fimage.png?alt=media&amp;token=d56948fb-d3e7-40c0-9877-66ac23c12515" alt="" width="452"><figcaption></figcaption></figure></div>

An existing group can be selected by using the drop-down functionality of the editor. Once all of the required groups are identified, pressing the **Save** button will add them to the list of external groups that will now be recognized by <code class="expression">space.vars.PRODUCT\_NAME</code>.

#### Removing Groups

To remove a group-role mapping, select a group and use the **Remove** command. When the group is only used in this mapping (not in any other), the group will be deleted entirely and cannot be used for other mappings anymore. When the group is used in other mappings as well, it will only be removed for this group-role mapping. The group is still usable for other (new) mappings:

<div align="left"><figure><img src="https://2723114352-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaBzbSV4obl284TJgE1Hg%2Fuploads%2FpfTcBFdmj08Bgg8FssYH%2Fimage.png?alt=media&amp;token=25dab320-bed2-47a4-b26e-36cf994b6480" alt="" width="483"><figcaption></figcaption></figure></div>
