Skip to main content

The four default roles

Protect ships with four read-only default roles. Their summary headers (from Settings → Roles → View) are: Default roles cannot be edited. To deviate from these grants, Create Role (button top-right of Settings → Roles) and configure each permission area.

Permission areas

Each role’s permissions are grouped into nine collapsible sections. Each section shows a single high-level badge (Full access / Partial write access / Partial view / View access / No access) and expands to per-item settings (View / View and manage / Manage / None / etc.). The nine sections — in the order they appear in the Roles editor — are:
  1. Data Visibility — Device, User, Network Device Visibility scopes
  2. Studio — Reporting / dashboards permission
  3. Device Inventory — Saved views, columns, notes, X-Ray, Action Center, Saved-View Actions, Automation Templates
  4. Vitals — Vitals, Workflow Automation, Vitals Issues
  5. User Inventory — Saved views, columns, user actions
  6. Browser Extension — Login access
  7. Reports — Reports / Scheduled Reports / Previous Reports
  8. User Management — Users, Roles, Teams, SSO Setup
  9. Settings — Integrations, Tags, API Keys, Misc, Audit Log, Audit Log Notes, IP Locations, Pin Data

Section badge matrix

How each default role scores across the nine sections:

Selected per-item details

Where the section badge masks meaningful differences, here are the per-item values seen live. None means the role can’t perform that action at all.

Device Inventory

* The live UI label currently reads “Automation Tempalates outside my scope” (typo).

Vitals

User Inventory

Reports

User Management

Settings

Studio and Browser Extension

Single-item sections:

Data Visibility

All four defaults have All for Device / User / Network Device Visibility. Restricting visibility is something you do per user (data filter) or by building a custom role.
Tenant policy may vary. Default roles are the same across all tenants; custom roles you create are tenant-specific. Always open Settings → Roles → View on the specific role for the exact configuration in your tenant.

Custom roles

Click Create Role at the top-right of Settings → Roles to clone-and-edit a default into a custom role. You can also restrict Device / User / Network Device Visibility to a saved view, giving you data-level filtering on top of capability filtering.

See also

Access Control

Conceptual model

Settings → Roles

Manage roles

Settings → Users

Assign roles and filters