> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Role Permissions Matrix

> Side-by-side comparison of what each default role can do, verified against the live Roles editor

## The four default roles

Protect ships with four read-only default roles. Their summary headers (from [Settings → Roles](/settings/roles) → View) are:

| Role               | Summary text                                                                                 |
| ------------------ | -------------------------------------------------------------------------------------------- |
| **Super Admin**    | Grants the users the highest level of privilege in the platform.                             |
| **Analyst**        | Grants users a moderate level of privilege, allowing them to perform in-depth data analysis. |
| **Viewer**         | Grants users read-only access to the platform.                                               |
| **Limited Viewer** | Grants the users the lowest level of privilege in the platform.                              |

Default roles cannot be edited. To deviate from these grants, **Create Role** (button top-right of Settings → Roles) and configure each permission area.

## Permission areas

Each role's permissions are grouped into nine collapsible sections. Each section shows a single high-level badge (Full access / Partial write access / Partial view / View access / No access) and expands to per-item settings (View / View and manage / Manage / None / etc.).

The nine sections — in the order they appear in the Roles editor — are:

1. **Data Visibility** — Device, User, Network Device Visibility scopes
2. **Studio** — Reporting / dashboards permission
3. **Device Inventory** — Saved views, columns, notes, X-Ray, Action Center, Saved-View Actions, Automation Templates
4. **Vitals** — Vitals, Workflow Automation, Vitals Issues
5. **User Inventory** — Saved views, columns, user actions
6. **Browser Extension** — Login access
7. **Reports** — Reports / Scheduled Reports / Previous Reports
8. **User Management** — Users, Roles, Teams, SSO Setup
9. **Settings** — Integrations, Tags, API Keys, Misc, Audit Log, Audit Log Notes, IP Locations, Pin Data

## Section badge matrix

How each default role scores across the nine sections:

| Section           | Super Admin | Analyst              | Viewer               | Limited Viewer |
| ----------------- | ----------- | -------------------- | -------------------- | -------------- |
| Data Visibility   | Full access | Full access          | Full access          | Full access    |
| Studio            | Full access | Partial write access | View access          | No access      |
| Device Inventory  | Full access | Partial write access | Partial write access | Partial view   |
| Vitals            | Full access | Full access          | View access          | Partial view   |
| User Inventory    | Full access | Full access          | Partial write access | Partial view   |
| Browser Extension | Full access | Full access          | Full access          | No access      |
| Reports           | Full access | Full access          | No access            | No access      |
| User Management   | Full access | Partial view         | Partial view         | No access      |
| Settings          | Full access | Partial write access | Partial view         | Partial view   |

## Selected per-item details

Where the section badge masks meaningful differences, here are the per-item values seen live. **None** means the role can't perform that action at all.

### Device Inventory

| Item                                       | Super Admin                | Analyst                    | Viewer | Limited Viewer |
| ------------------------------------------ | -------------------------- | -------------------------- | ------ | -------------- |
| Global Devices Saved Views                 | View and manage            | View and manage            | View   | None           |
| Team Devices Saved Views                   | View and manage            | View and manage            | View   | None           |
| Private Devices Saved Views                | Manage                     | Manage                     | Manage | None           |
| Device Notes                               | View and manage            | View and manage            | View   | None           |
| Devices Columns                            | View and manage            | View and manage            | View   | View           |
| Device Actions (Split/Merge/Change State)  | Split, Merge, Change State | Split, Merge, Change State | None   | None           |
| X-Ray                                      | View                       | View                       | View   | None           |
| Software Rules                             | View and manage            | View and manage            | View   | None           |
| Action Center                              | View and manage            | View and manage            | View   | None           |
| Global / Team / Private Saved View Actions | View and manage            | View and manage            | View   | None           |
| Saved View Actions outside my scope        | View and manage            | View                       | View   | None           |
| Automation Templates outside my scope\*    | Manage                     | None                       | None   | None           |

\* The live UI label currently reads "Automation Tempalates outside my scope" (typo).

### Vitals

| Item                | Super Admin             | Analyst                 | Viewer | Limited Viewer |
| ------------------- | ----------------------- | ----------------------- | ------ | -------------- |
| Vitals              | View and manage         | View and manage         | View   | View           |
| Workflow Automation | View and manage         | View and manage         | View   | None           |
| Vitals Issues       | View, assign and action | View, assign and action | View   | View           |

### User Inventory

| Item                            | Super Admin                | Analyst                    | Viewer | Limited Viewer |
| ------------------------------- | -------------------------- | -------------------------- | ------ | -------------- |
| Global / Team Users Saved Views | View and manage            | View and manage            | View   | None           |
| Private Users Saved Views       | Manage                     | Manage                     | Manage | None           |
| Users Columns                   | View and manage            | View and manage            | View   | View           |
| User Actions                    | Split, Merge, Change State | Split, Merge, Change State | None   | None           |

### Reports

| Item              | Super Admin | Analyst  | Viewer | Limited Viewer |
| ----------------- | ----------- | -------- | ------ | -------------- |
| Reports           | Export      | Export   | None   | None           |
| Scheduled Reports | Manage      | Manage   | None   | None           |
| Previous Reports  | Download    | Download | None   | None           |

### User Management

| Item      | Super Admin             | Analyst | Viewer | Limited Viewer |
| --------- | ----------------------- | ------- | ------ | -------------- |
| Users     | View and manage         | View    | View   | None           |
| Roles     | View, assign and manage | View    | View   | None           |
| Teams     | View and manage         | View    | View   | None           |
| SSO Setup | Manage                  | None    | None   | None           |

### Settings

| Item            | Super Admin              | Analyst          | Viewer | Limited Viewer |
| --------------- | ------------------------ | ---------------- | ------ | -------------- |
| Integrations    | View, refresh and manage | View and refresh | View   | View           |
| Tags            | View and manage          | View and manage  | View   | View           |
| API Keys        | Manage                   | None             | None   | None           |
| Misc            | Manage                   | None             | None   | None           |
| Audit Log       | View own and others      | View own         | None   | None           |
| Audit Log Notes | View and manage          | View and manage  | None   | None           |
| IP Locations    | View and manage          | View             | View   | View           |
| Pin Data        | Manage                   | None             | None   | None           |

## Studio and Browser Extension

Single-item sections:

| Section item             | Super Admin             | Analyst         | Viewer | Limited Viewer |
| ------------------------ | ----------------------- | --------------- | ------ | -------------- |
| Studio                   | View, create and manage | View and create | View   | None           |
| Browser Extension Access | Login                   | Login           | Login  | None           |

## Data Visibility

All four defaults have **All** for Device / User / Network Device Visibility. Restricting visibility is something you do per user (data filter) or by building a custom role.

<Info>
  **Tenant policy may vary.** Default roles are the same across all tenants; custom roles you create are tenant-specific. Always open [Settings → Roles](/settings/roles) → View on the specific role for the exact configuration in your tenant.
</Info>

## Custom roles

Click **Create Role** at the top-right of [Settings → Roles](/settings/roles) to clone-and-edit a default into a custom role. You can also restrict **Device / User / Network Device Visibility** to a saved view, giving you data-level filtering on top of capability filtering.

## See also

<CardGroup cols={3}>
  <Card title="Access Control" icon="users-gear" href="/access-control">
    Conceptual model
  </Card>

  <Card title="Settings → Roles" icon="shield" href="/settings/roles">
    Manage roles
  </Card>

  <Card title="Settings → Users" icon="user" href="/settings/users">
    Assign roles and filters
  </Card>
</CardGroup>
