> For the complete documentation index, see [llms.txt](https://docs.aisera.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.aisera.com/aisera-platform/tenant-setup/aisera-platform-configuration/aisera-platform-roles-and-permissions/managing-user-roles.md).

# Managing User Roles

## Managing Roles

The Aisera Platform offers several built-in roles, but you can also create and manage custom permissions to suit your specific needs.

{% hint style="warning" %}
When you create roles and permissions, it is a best practice to document the reasons with examples of each role and permission you created. Although you can see the permissions in the UI, it may be difficult for you to determine where a specific restriction is coming from.
{% endhint %}

### Creating a Custom Role

1. Open **Settings > User Accounts** from the left navigation menu
2. Select the **Roles** tab at the top of the **User Accounts** window
3. Choose **+ Create Role**
4. Enter a **Name** and **Description** for the role.&#x20;
5. Navigate to the **Features and Permissions** tab and apply the appropriate level of privilege for each item.

**Configuring entity-level permissions**

If you set a feature to **Restricted**, you can configure access for individual entities within that feature from the feature's tab in the role window.

1. Select the tab for the feature you set to **Restricted** from the left panel of the role window.
2. For each entity, select **Read**, **Write**, or **None**.
3. Click **OK** to save your changes.

### Editing a Custom Role

{% hint style="info" %}
System and default roles are not editable. You can only modify custom roles.
{% endhint %}

1. Open **Settings > User Accounts** from the left navigation menu
2. Select the **Roles** tab at the top of the **User Accounts** window
3. Select the role you want to modify
4. Click on the **pencil icon** in the top right to see the **Edit Role** window
5. Change the **Name**, **Description** or **Privileges** for the role
6. Click **Ok** to save changes

### Deleting a Custom Role

{% hint style="info" %}
System and default roles cannot be deleted. Only custom roles can be removed.
{% endhint %}

1. Open **Settings > User Accounts** from the left navigation menu
2. Select the **Roles** tab at the top of the **User Accounts** window
3. Select the role you want to delete
4. Click on the **trash icon** in the top right to see the **Delete Role** window
5. Click **Ok** to confirm deletion of the role

**Assign Application Access for PII by Role**

You can give member of a custom role access to Personal Identifiable Information (PII), by choosing the **piis** checkbox for your new role.

<div align="left"><figure><img src="https://docs.aisera.com/~gitbook/image?url=https%3A%2F%2F2983236984-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FiZkLJr3EjXkd2tHYiQJP%252Fuploads%252FANMpscRlZ8WA4lJv7VTZ%252Funknown.png%3Falt%3Dmedia%26token%3Deb9d3960-1461-4715-8afd-9c32a76f3e33&#x26;width=300&#x26;dpr=4&#x26;quality=100&#x26;sign=1c1f3a88&#x26;sv=2" alt="" width="563"><figcaption></figcaption></figure></div>
