> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getray.info/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & Permissions

> The Roles & Permissions screen is where an admin creates portal roles (name, type, location), chooses each role's features, and assigns or unassigns users. Found under Administration → Roles & Permissions in the RAY admin portal.

## Summary

The **Roles & Permissions** screen in the RAY admin portal controls who can use the portal and what
they can see. It has two tabs. **Role Assignments** lists which user holds which role, and is where
users are assigned to or removed from roles. **Roles** lists the roles themselves, and is where
roles are created and deleted. Each role's detail page has a **Features** tab (what the role can
access) and an **Assignments** tab (who holds the role). For how roles, features and locations
combine into access, see [Roles and permissions](/getting-started/roles-and-permissions).

## Where to find the Roles & Permissions screen

* Menu: **Administration → Roles & Permissions** (Arabic: **إدارة ← الأدوار والأذونات**)
* Tabs: **Role Assignments** (تعيين الأدوار) and **Roles** (أدوار)
* Clicking a role in the **Roles** tab opens the role's detail page.

## Who can access the Roles & Permissions screen

The Roles & Permissions menu entry is shown only to users with an **Admin** role that includes the
administration feature. The same feature also shows **Features & Audiences**, **Profile
Customization** and **Organization Settings**.

## Role Assignments tab

The **Role Assignments** tab lists one row per user-and-role pair. A user with three roles appears
in three rows.

| Column   | Meaning                                                           |
| -------- | ----------------------------------------------------------------- |
| **User** | The user's name and profile card.                                 |
| **Role** | The role held. Clicking the role name opens the role detail page. |
| Actions  | **Unassign** removes the user from that role.                     |

The Role Assignments tab can be filtered by **User** (search by name or email) and by **Role**.

## Roles tab

The **Roles** tab lists every role.

| Column       | Meaning                                                             |
| ------------ | ------------------------------------------------------------------- |
| **Role**     | Name of the role.                                                   |
| **Type**     | **Admin**, **Security** or **Operator**.                            |
| **Location** | **Global**, or the name of the one location the role is limited to. |
| Actions      | **Delete** the role. Clicking a row opens the role detail page.     |

## Role fields

| Field        | Required | Meaning and rules                                                                                                                                           |
| ------------ | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Role**     | Yes      | Name of the role, for example "Front desk" or "Tower A managers". Can be changed later.                                                                     |
| **Type**     | Yes      | **Admin** (المشرف على الموقع), **Security** (الأمن) or **Operator** (مشغّل). **Admin** is selected by default. Cannot be changed after the role is created. |
| **Location** | Yes      | **Global** (all locations) or **Specific Location** plus one location. Cannot be changed after the role is created.                                         |
| **Features** | No       | The features the role grants, set on the role detail page.                                                                                                  |

## How to create a role

1. Open **Administration → Roles & Permissions** and select the **Roles** tab.
2. Click **Add**.
3. Enter the **Role** name.
4. Choose the **Type**: **Admin**, **Security** or **Operator**.
5. Choose the **Location**: **Global**, or **Specific Location** and then the location.
6. Click **Save**. The portal opens the new role's detail page.
7. In the **Features** tab, tick the features the role should grant.
8. In the **Assignments** tab, click **Assign** to add users.

When a specific location is selected in the portal header, a new role is always created for that
location, and the **Location** choice is locked. To create a **Global** role, first select
**Global** in the location selector in the portal header.

## How to choose the features of a role

1. Open **Administration → Roles & Permissions**, select the **Roles** tab, and click the role.
2. Open the **Features** tab. It lists the features available for the role's type, sorted by name.
3. Tick a feature to grant it, or untick it to remove it.

Each tick or untick is saved immediately, with the message "Your item has been updated
successfully"; there is no Save button. The features listed depend on the role's **Type**, so an
Operator or Security role lists fewer features than an Admin role. Feature names follow any custom
name set in [Features & Audiences](/administration/features-and-audiences).

## How to assign a user to a role

A user can be assigned from either tab.

From the **Role Assignments** tab:

1. Open **Administration → Roles & Permissions** and select the **Role Assignments** tab.
2. Click **Assign**.
3. Choose the user in **Select a User** and the **Role**.
4. Click **Save**.

From a role's detail page:

1. Open the role from the **Roles** tab.
2. Open the **Assignments** tab and click **Assign**.
3. Choose the user in **Select a User**.
4. Click **Save**.

## How to remove a user from a role

1. Open **Administration → Roles & Permissions** and select the **Role Assignments** tab (or open the
   role and select its **Assignments** tab).
2. Click **Unassign** on the user's row.
3. Confirm in the dialog titled "Unassign" followed by the user's first name, "From" and the role name.

The user loses the screens that only that role gave them. Their other roles are not affected.

## How to rename or delete a role

* To rename a role, open the role detail page and edit the title. The **Type** and **Location** are
  shown on the detail page but cannot be edited.
* To delete a role, click **Delete** on its row in the **Roles** tab and confirm.

## Common questions about Roles & Permissions

### How do I give a new staff member access to the portal?

Assign the staff member to a role in **Administration → Roles & Permissions**. The staff member must
already exist as a user. If no existing role has the right type, location and features, create one
first. Use the [Portal map](/getting-started/portal-map) to see which role type and feature each
screen needs.

### How do I change a role from Operator to Admin?

A role's **Type** cannot be changed after creation. Create a new role with the **Admin** type and the
same features, move the users to it with **Assign** and **Unassign**, then delete the old role.

### How do I limit an admin to one building or site?

Roles can be limited to one location, not to one building. Create the role with **Specific
Location** and choose the location. Locations are managed in
[Multi Location Setup](/administration/multi-location-setup).

### Why can't I find a feature in a Security or Operator role?

The features listed in a role's **Features** tab depend on the role's **Type**. A Security or
Operator role lists only some features. If the feature you need is not listed, create an Admin role
for it instead; check the [Portal map](/getting-started/portal-map) to see which role types a
screen supports.

### Why can't I create a Global role?

The **Location** choice is locked to the location selected in the portal header. Select **Global**
in the header location selector, then create the role. If **Global** is not offered in the header,
your own roles are all limited to specific locations.

## Related pages

* [Roles and permissions](/getting-started/roles-and-permissions): how role types, features and locations combine into access.
* [Portal map](/getting-started/portal-map): the role type and feature each screen needs.
* [Features & Audiences](/administration/features-and-audiences): switching features on for the organization and renaming them.
* [Multi Location Setup](/administration/multi-location-setup): the locations a role can be limited to.
