---
title: "Managing Roles & Permissions"
source: /gcxone/admin-guide/roles-permissions
locale: en
updated: 2026-09-08
---
## Understanding RBAC in GCXONE

GCXONE uses role-based access control (RBAC) to determine exactly what each user can see and do. Every user must be assigned a role — without one, they land on a blocked screen immediately after login. Roles combine three things: the modules they can access, the actions they can perform within each module, and which customers and sites they can operate on.

## The Role Management Screen

Navigate to **Settings → Roles**. The Role Management screen lists every role in the tenant with user counts and actions.

## Creating a Custom Role

Navigate to **Settings → Roles → Configure New Role**.

### Step 1 — Role Information

Enter the role **Name** and **Description**.

Name roles specifically — it's more useful in audit logs than *"Operator 2"*.

![Configure New Role wizard — Role Information step](/api/media/file/d8a9d1e2fb049b69e9be081db3663c6b0b74b138-1517x821.png)

*The role wizard opens with Role Information. Name the role specifically.*

### Step 2 — Users

Select which users should be assigned to this role from the searchable user grid. Use Select All, Remove All, or search to manage the list in bulk.

### Step 3 — Module Privileges

Work through each platform module in the left panel, grouped into Core, Feature, and System. Grant or remove specific capabilities per module — Dashboard, Configuration, Video Activity Search, Marketplace, Camera Actions & Alarm Handling, Talos, and more.

![Configuration module permission settings](/api/media/file/8e841d88885746fa1c2bf1533848366ed331042f-1527x832.png)

*Each module has granular capabilities. The Configuration tab controls adding customers and editing device credentials — Admin only.*

### Step 4 — Entity Access

Set which customers, sites, and devices this role can operate on. Enable **Include Children** on any parent to auto-include all sub-entities — including future additions.

## Entity Access Modes

### No Entity Access

Users assigned this role get no entities by default. Assign entities per user afterward via Edit Entity Access. Best for a shared role where each user needs a different set of customers or sites.

### Selected Entities

Assign specific customers and sites. Enable **Include Children** to auto-include any sub-entities added in future.

![Selected entities with Include Children toggle](/api/media/file/72b3cf2594eba546801ac39ba104600c861eb837-1843x809.png)

*Selected Entities mode with Include Children toggle.*

### Full Access

Role sees every customer and site in the tenant. Use only for internal admin accounts.

![Full access for all entities enabled](/api/media/file/e315cfcd16972fa7354537053afd1db012d2ea22-1836x812.png)

*Full Access mode. Use only for internal admin accounts.*

## Role Configuration Reference

- **Super Admin** — All modules. Entity: Full Access.
- **Admin** — Dashboard, Configuration, User Management, Roles & Permissions, Reports. Cannot access billing.
- **Operator** — Configuration (view-only), Camera Actions & Alarm Handling, Dashboard, HealthCheck, ZenMode, Video Activity Search, Map, Video Viewer. No Settings, Talos, Marketplace, or Genie access.
- **Installer** — Configuration (Devices, Sensors, Network Settings), Video Viewer (Live). Cannot manage users or roles.
- **End User** — Dashboard, basic Configuration view, Reports, Video Viewer (Live), Arm/Disarm for assigned devices. No ability to change settings.

## Per-User Entity Access Override

Customize entity access for an individual user without creating a separate role. This is where **Override** and **Merge** mode — the two ways to layer a user's own entities on top of their role — come in:

1. Navigate to **Settings → Roles → Edit Entity Access** and select the user from the list — or, for a shortcut straight to one user, go to **Settings → Users**, open their Actions menu, and choose **Edit User Entities**.
2. Choose **Override** or **Merge** mode.
3. Add or remove specific customers, sites, or devices.
4. Save — the change applies immediately.

## Post-Migration Role Recovery

### User Sees Access Denied on a Module They Had Before

1. Open their role → Module Privileges → verify the capability was not removed during the role edit.
2. Check Audit Log → filter by user and date.

### User Cannot See a Recently Added Site

1. Check if their role uses Selected Entities without Include Children.
2. Either enable Include Children on the parent customer, or manually add the new site to the role.

### User Has Access to Sites They Should Not

1. Check for active Merge overrides on the user.
2. Navigate to **Settings → Roles → Edit Entity Access**.
3. Remove the unwanted Merge entries.

## Related Resources

- For the conceptual overview of RBAC, roles, and entity access, refer to [Understanding Roles & Permissions](/gcxone/platform-fundamentals/roles-and-permissions)
- For the full catalog of every individual permission, refer to [Privileges](/gcxone/platform-fundamentals/privilege-deep-dive)

<!-- Not represented in Markdown: callout. Read the page at /gcxone/admin-guide/roles-permissions -->
