> For the complete documentation index, see [llms.txt](https://docs.arksspr.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.arksspr.com/master/arksspr-user-guide/role-management.md).

# ROLE MANAGEMENT

The **Role Management** page is used to assign and manage administrative permissions in ARKSSPR. A user can be a member of multiple roles. Permissions are evaluated cumulatively based on all assigned roles.

ARKSSPR provides the following administrative roles:

* Administrator
* Report Operator
* Help Desk
* Restricted User

***

### Administrator

The **Administrator** role has full administrative privileges across the ARKSSPR platform.

Administrators can perform the following actions:

* Change their password.
* Configure an alternate email address for two-factor authentication (2FA).
* Configure the default verification method used for password reset and account unlock operations.
* Register a mobile authenticator application by scanning a QR code.
* View and manage reports.
* Manage roles and role assignments.
* Configure system settings.
* Manage licenses.
* View system logs.
* Configure screen settings.
* View and manage user requests.

***

### Report Operator

The **Report Operator** role is responsible for reporting operations.

Users assigned to this role can:

* Change their password.
* Configure an alternate email address.
* Configure the default verification method.
* Register a mobile authenticator application.
* View reports.
* Create scheduled reports.
* Export reports.
* Send reports by email.

***

### Help Desk

The **Help Desk** role is responsible for managing user requests and support activities.

Users assigned to this role can:

* Change their password.
* Configure an alternate email address.
* Configure the default verification method.
* Register a mobile authenticator application.
* View user requests.
* Manage and close support tickets.

***

### Users

The **Users** category represents standard Active Directory users who are not assigned an administrative role.

Standard users can:

* Change their password.
* Configure an alternate email address.
* Configure the default verification method.
* Register a mobile authenticator application.

***

### Restricted User

The **Restricted User** role is intended for users or groups that should not have access to ARKSSPR.

Users assigned to this role:

* Cannot sign in to ARKSSPR.
* Cannot perform password management operations.
* Cannot access any administrative pages.
* Cannot use any permissions granted by other assigned roles.

> **Note**
>
> The **Restricted User** role overrides all other role assignments. If a user belongs to this role, all ARKSSPR permissions are denied.

<figure><img src="/files/FbVMd8r53s9rvyU6wgjn" alt=""><figcaption></figcaption></figure>

This page allows administrators to manage role assignments.

* The left pane displays the available roles.
* The right pane displays the users assigned to the selected role.
* Select **Add User** to assign additional users to the selected role or remove existing assignments.

User names shown in the documentation have been anonymized (for example, **DOMAIN\User1** and **DOMAIN\User2**).
