> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# What are roles and privileges?

export const DefinitionDescription = ({children}) => <dd className="definition-description">{children}</dd>;

export const DefinitionTerm = ({children}) => <dt className="definition-term">{children}</dt>;

export const DefinitionList = ({children}) => <dl className="definition-list">{children}</dl>;

Every [user](/docs/platform/concepts/what-is-a-user) on the platform has a role and a set of privileges. The role controls whether they can access the platform's administrative features. Privileges control which [perimeters](/docs/platform/concepts/what-is-a-perimeter) they can access and what they can do there.

## Roles

A user's role determines what actions they can take on the platform.

<DefinitionList>
  <DefinitionTerm>
    Admin
  </DefinitionTerm>

  <DefinitionDescription>
    Can manage the platform, including users, perimeters, compute, and the policies that govern them.
  </DefinitionDescription>

  <DefinitionTerm>
    Member
  </DefinitionTerm>

  <DefinitionDescription>
    Can work within the perimeters they've been granted access to, but cannot manage the platform itself. This is the default role.
  </DefinitionDescription>
</DefinitionList>

The role does not, on its own, grant access to any particular perimeter's work.

## Privileges

Privileges grant access to the work inside a perimeter. A user holds unique privileges for each perimeter they work in. A user might have Execute privileges on one perimeter, View on another, and no access to a third.

For example, a data scientist is typically a Member with Execute privileges on their team's perimeters, letting them run [workloads](/docs/platform/concepts/what-is-a-workload) there without any ability to manage the platform. This separation keeps everyday work and platform administration distinct; for instance, granting someone the ability to run workloads doesn't also give them control over the platform's configuration.

<DefinitionList>
  <DefinitionTerm>
    View
  </DefinitionTerm>

  <DefinitionDescription>
    Can see the results of workloads, read logs, and read artifacts in the perimeter.
  </DefinitionDescription>

  <DefinitionTerm>
    Execute
  </DefinitionTerm>

  <DefinitionDescription>
    Can run workloads and create artifacts in the perimeter.
  </DefinitionDescription>
</DefinitionList>

## Managing roles and privileges

Administrators assign roles and grant perimeter privileges.
