> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Default user roles

Oleria includes five built-in roles you can assign to users. Each role defines a specific set of permissions that controls what the user can see and do in the workspace. These default roles cannot be edited.

## Built-in roles

| Role                        | Description                                                                                                                                                                                                                                           |
| :-------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Administrator               | The most complete access level: user management, integrations, and administrative settings such as SSO configuration, webhooks, and OAuth applications. Some modules are view-only for every role, including Administrator, while they're rolled out. |
| Operator                    | Access to all Adaptive Security features and can manage connected integrations. Cannot manage workspace users.                                                                                                                                        |
| Analyst                     | View-only access to Adaptive Security and connected integrations. Suitable for read-only reporting and investigation.                                                                                                                                 |
| Governance Operator         | Access to all Governance features, including access reviews, identity lifecycle, access bundles, and access requests. Can view connected integrations but not modify them. Cannot manage workspace users.                                             |
| Identity Lifecycle Operator | Access to identity lifecycle, access bundles, and access requests. Can view connected integrations but not modify them. Cannot run access reviews or manage workspace users.                                                                          |

## When to assign each role

**Administrator** - assign to security leads and workspace owners who need to add users, configure integrations, and manage workspace settings, including SSO configuration, ticketing and messaging setup, webhooks, and OAuth applications. Keep the number of administrators small.

**Operator** - assign to team members who need to connect integrations, manage OAuth applications, and use Adaptive Security features (Access Graph, Risk Monitoring, Activity Analysis, Account Utilization) but should not manage who has access to Oleria itself.

**Analyst** - assign to stakeholders who need to view findings and run investigations but should not make configuration changes. This is the right role for auditors, compliance reviewers, or team members who consume reports.

**Governance Operator** - assign to identity governance and compliance owners who run access reviews and manage identity lifecycle, access bundles, and access requests, but should not change integrations or manage who has access to Oleria. This role can view connected integrations for context without modifying them.

**Identity Lifecycle Operator** - assign to identity lifecycle owners who manage identity lifecycle, access bundles, and access requests, but should not run access reviews, change integrations, or manage who has access to Oleria. This role can view connected integrations for context without modifying them.

## Role permissions

| Module                                                 | Administrator                                                                                                        | Operator                                                                       | Analyst                                  | Governance Operator                                            | Identity Lifecycle Operator                                    |
| :----------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------- | :----------------------------------------------------------------------------- | :--------------------------------------- | :------------------------------------------------------------- | :------------------------------------------------------------- |
| Manage Users                                           | View all users, Add a user, Update user, Remove user                                                                 | No access                                                                      | No access                                | No access                                                      | No access                                                      |
| Integrations                                           | View all integrations, Add integration, Update integration, Delete integration                                       | View all integrations, Add integration, Update integration, Delete integration | View all integrations                    | View all integrations                                          | View all integrations                                          |
| [Ticketing setup](/workspace/ticketing-overview)       | Add, view, and delete the ticketing connection                                                                       | No access                                                                      | No access                                | No access                                                      | View the ticketing connection                                  |
| Messaging setup                                        | Add, view, update, and delete the messaging connection                                                               | No access                                                                      | No access                                | View the messaging connection                                  | View the messaging connection                                  |
| Tickets                                                | Create, view, update, and delete tickets                                                                             | Create, view, update, and delete tickets                                       | Create, view, update, and delete tickets | Create, view, update, and delete tickets                       | Create, view, update, and delete tickets                       |
| [SSO configuration](/administration/sso-configuration) | Manage SSO configuration                                                                                             | No access                                                                      | No access                                | No access                                                      | No access                                                      |
| Access Reviews                                         | Manage access reviews                                                                                                | View                                                                           | View                                     | Manage access reviews                                          | No access                                                      |
| Identity Lifecycle, Access Bundles & Access Requests   | Manage identity lifecycle, access bundles, and access requests, including overriding access request review decisions | View                                                                           | View                                     | Manage identity lifecycle, access bundles, and access requests | Manage identity lifecycle, access bundles, and access requests |
| Employee-to-account linking                            | Link and unlink                                                                                                      | Link and unlink                                                                | No access                                | Link and unlink                                                | Link and unlink                                                |
| Remediation & Action Center                            | View action, undo action, and perform remediation actions (for example, disable account, revoke access)              | View action                                                                    | View action                              | View action                                                    | View action                                                    |
| Access Graph                                           | View                                                                                                                 | View                                                                           | View                                     | View                                                           | View                                                           |
| Risk Monitoring                                        | View, Export CSV                                                                                                     | View, Export CSV                                                               | View, Export CSV                         | View, Export CSV                                               | View, Export CSV                                               |
| Activity Analysis                                      | View, Export CSV                                                                                                     | View, Export CSV                                                               | View, Export CSV                         | View, Export CSV                                               | View, Export CSV                                               |
| Account Utilization                                    | View, Export CSV                                                                                                     | View, Export CSV                                                               | View, Export CSV                         | View, Export CSV                                               | View, Export CSV                                               |
| Group Analytics                                        | View, Export CSV                                                                                                     | View, Export CSV                                                               | View, Export CSV                         | View, Export CSV                                               | View, Export CSV                                               |
| Access Inventory                                       | View, Export CSV                                                                                                     | View, Export CSV                                                               | View, Export CSV                         | View, Export CSV                                               | View, Export CSV                                               |
| OAuth Applications                                     | Manage OAuth applications                                                                                            | Manage OAuth applications                                                      | No access                                | View                                                           | View                                                           |
| Webhooks                                               | Manage webhooks                                                                                                      | No access                                                                      | No access                                | No access                                                      | No access                                                      |
| Taskflows                                              | Manage taskflows                                                                                                     | View                                                                           | View                                     | View                                                           | View                                                           |
| AI Agent Gateway                                       | View                                                                                                                 | No access                                                                      | No access                                | No access                                                      | No access                                                      |
| Notifications                                          | View                                                                                                                 | View                                                                           | View                                     | View                                                           | View                                                           |

<Note>
  Only Administrators can configure approval chains for access requests and override an access request review decision. Governance Operators and Identity Lifecycle Operators can otherwise fully manage access request configuration.
</Note>

<Note>
  The AI Agent Gateway is currently view-only for every role, including Administrator, while the feature rolls out.
</Note>

## Contact us

For questions, contact us at [support@oleria.com](mailto:support@oleria.com).
