The four default roles
Protect ships with four read-only default roles. Their summary headers (from Settings → Roles → View) are:
Default roles cannot be edited. To deviate from these grants, Create Role (button top-right of Settings → Roles) and configure each permission area.
Permission areas
Each role’s permissions are grouped into nine collapsible sections. Each section shows a single high-level badge (Full access / Partial write access / Partial view / View access / No access) and expands to per-item settings (View / View and manage / Manage / None / etc.). The nine sections — in the order they appear in the Roles editor — are:- Data Visibility — Device, User, Network Device Visibility scopes
- Studio — Reporting / dashboards permission
- Device Inventory — Saved views, columns, notes, X-Ray, Action Center, Saved-View Actions, Automation Templates
- Vitals — Vitals, Workflow Automation, Vitals Issues
- User Inventory — Saved views, columns, user actions
- Browser Extension — Login access
- Reports — Reports / Scheduled Reports / Previous Reports
- User Management — Users, Roles, Teams, SSO Setup
- Settings — Integrations, Tags, API Keys, Misc, Audit Log, Audit Log Notes, IP Locations, Pin Data
Section badge matrix
How each default role scores across the nine sections:Selected per-item details
Where the section badge masks meaningful differences, here are the per-item values seen live. None means the role can’t perform that action at all.Device Inventory
* The live UI label currently reads “Automation Tempalates outside my scope” (typo).
Vitals
User Inventory
Reports
User Management
Settings
Studio and Browser Extension
Single-item sections:Data Visibility
All four defaults have All for Device / User / Network Device Visibility. Restricting visibility is something you do per user (data filter) or by building a custom role.Tenant policy may vary. Default roles are the same across all tenants; custom roles you create are tenant-specific. Always open Settings → Roles → View on the specific role for the exact configuration in your tenant.
Custom roles
Click Create Role at the top-right of Settings → Roles to clone-and-edit a default into a custom role. You can also restrict Device / User / Network Device Visibility to a saved view, giving you data-level filtering on top of capability filtering.See also
Access Control
Conceptual model
Settings → Roles
Manage roles
Settings → Users
Assign roles and filters