> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

## Roles

Roles determine the level of access a user has within Anaconda Server. Some preconfigured roles have been embedded into Keycloak to provide users with varying levels of access to the software’s available features. If the default Anaconda roles described here do not suit your use case, you can create a custom role for your users.

### Permission levels

There are four levels of permissions available for Anaconda Server:

* **Read**: provides the ability to view the associated feature.
* **Write**: provides the ability to view and create new assets of the associated feature.
* **Manage**: provides the ability to view, create, and edit assets of the associated feature.
* **None**: removes permissions for the associated feature.

### Permission categories

Each permission category is associated with some feature of Anaconda Server. The available permission categories are:

* **Channels**: grants interaction with channels
* **Default Channel**: grants interaction with the user’s default channel
* **Channel Groups**: grants interaction with channel groups
* **Channel Mirrors**: grants interaction with channel mirrors
* **Subchannels**: grants interaction with subchannels
* **Subchannel Groups**: grants interaction with subchannel groups
* **Subchannel Mirrors**: grants interaction with subchannel mirrors
* **Artifacts**: grants interaction with artifacts
* **CVE**: grants interaction with CVEs
* **Roles**: grants interaction with roles
* **Audit Logs**: (read permissions only) grants admins permissions to download user audit logs report

### Preconfigured roles

Anaconda Server contains the following preconfigured roles for the Dev realm:

* **everyone**: A non-authenticated user. Allows visibility into public channel and subchannel contents as well as group membership.
* **author**: An authenticated user. Allows users to create new channels and subchannels, and provides user level access to your Team Notebooks server.
* **admin**: The administrator role has full management permissions over all the features of Anaconda Server. The admin role is responsible for creating and maintaining mirrors in addition to managing users and CVE data. This role also provides admin level permissions to your Team Notebooks server.
* **Notebooks admin**: An administrator role for the Team Notebooks server.
* **Notebooks author**: Allows users to access the Team Notebooks server.

<Note>
  The admin role is not visible through Anaconda Server UI.
</Note>

## Managing Roles

For customers on the Business plan, Anaconda has two main user personas: IT administrators and everyone else. As an IT administrator, you are responsible for establishing and maintaining the users’ accounts and the resources available to them within Anaconda Server.

### Creating custom roles

To create a custom role, complete the following steps:

1. Log in to Anaconda Server.

2. Navigate to the **User Management** page.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/AzA0BFAhlbKpAtkn/images/as_user_mgmt_nav.png?fit=max&auto=format&n=AzA0BFAhlbKpAtkn&q=85&s=e01bdc6a390381477a3925fc18876418" alt="" width="1922" height="840" data-path="images/as_user_mgmt_nav.png" />
   </Frame>

3. Click the icon to the right of **User Roles**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/thX2NnwjYcGQ9mji/images/as_create_role.png?fit=max&auto=format&n=thX2NnwjYcGQ9mji&q=85&s=111a7566568f1ec1a14acef80fa62ff9" alt="" width="1922" height="642" data-path="images/as_create_role.png" />
   </Frame>

4. Enter a unique name and set the permission levels for your custom role.

5. Click **Create**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/thX2NnwjYcGQ9mji/images/as_custom_role.png?fit=max&auto=format&n=thX2NnwjYcGQ9mji&q=85&s=c37da0b2f0f0bf5690cb16fe310b8c9d" alt="" width="1922" height="836" data-path="images/as_custom_role.png" />
   </Frame>

### Editing role permissions

To edit your role permissions, complete the following steps:

1. Log in to Anaconda Server.
2. Navigate to the **User Management** page.
3. Select an existing role from the list.
4. Edit the role name and permissions as needed.
5. Click **Update**.

### Assigning a role to a user

To assign a role to a user, complete the following steps:

1. [Log in to the Keycloak administrative console](/docs/psm-on-prem/6.5.3/admin/keycloak_config/user_roles#accessing-the-keycloak-administrative-console).
2. Navigate to the dev realm.
3. Select **Users** from the left-hand navigation.
4. Select a user to assign roles to.
5. Select the **Role Mapping** tab.
6. Click **Assign role**.
7. Select the roles you need to add to your user, then click **Assign**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/QCWY8EsGZWJYinOU/images/kc_assign_role.png?fit=max&auto=format&n=QCWY8EsGZWJYinOU&q=85&s=4b26fc0388441f56078b94a4d62c4023" alt="" width="1922" height="944" data-path="images/kc_assign_role.png" />
   </Frame>

### Deleting a role

To delete a role, complete the following steps:

1. Log in to Anaconda Server.

2. Navigate to the **User Management** page.

3. Click the <Icon icon="circle-xmark" iconType="regular" /> icon to the right of the role you want to delete.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/4qznYPKo21deuO4H/images/as_delete_role.png?fit=max&auto=format&n=4qznYPKo21deuO4H&q=85&s=f3dc28a76b7a559bc96bf3b6ebd21738" alt="" width="1922" height="705" data-path="images/as_delete_role.png" />
   </Frame>

4. Click **Delete** to confirm that you want to delete the role.

### Composite roles

A composite role is built from other existing roles and provides the aggregated permissions of all the roles it’s composed of.

In the following example, we create a composite role that allows an admin user on the master realm to manage users on the dev realm. However, you can use this same process to create admin roles with restricted access to managing other things on the dev realm.

To create an admin role with restricted permissions, complete the following steps:

1. [Log in to the Keycloak administrative console](/docs/psm-on-prem/6.5.3/admin/keycloak_config/user_roles#accessing-the-keycloak-administrative-console).

2. Navigate to the master realm.

3. Select **Realm roles** from the left-hand navigation.

4. Click **Create Role**.

5. Enter a name for your role and provide a brief description of its intended use.

6. Click **Save**. More tabs appear.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/_0MqQ39OoYOKQTk5/images/kc_composite_role_create.png?fit=max&auto=format&n=_0MqQ39OoYOKQTk5&q=85&s=237463caeed5e018bad9bacf448351c4" alt="" width="1922" height="791" data-path="images/kc_composite_role_create.png" />
   </Frame>

7. Open the **Action** dropdown menu and select **Add associated roles**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/_0MqQ39OoYOKQTk5/images/kc_composite_role_assign.png?fit=max&auto=format&n=_0MqQ39OoYOKQTk5&q=85&s=7ab8bee6eeb8bf969e834b200afa716b" alt="" width="1922" height="786" data-path="images/kc_composite_role_assign.png" />
   </Frame>

8. If necessary, open the filter dropdown menu and select **Filter by clients**.

   To achieve the preferred result of creating an admin user that can only view and manage users on the dev realm, select the following available client roles:

   * manage-users
   * query-users
   * view-users

9. Select available roles to associate their permissions with this composite role.

10. Click **Assign**.

### Setting/updating default roles

Default roles are permissions that are automatically applied to any newly created or imported user. Each realm has its own set of default roles that are applied to users created/imported on that realm. These are composite roles, and must be constructed of other existing roles.

To set the default roles, complete the following steps:

1. [Log in to the Keycloak administrative console](/docs/psm-on-prem/6.5.3/admin/keycloak_config/user_roles#accessing-the-keycloak-administrative-console).

2. Verify you are on the realm you need to set default roles for.

3. Select **Realm settings** from the left-hand navigation.

4. Select the **User registration** tab.

5. Click **Assign role**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/_0MqQ39OoYOKQTk5/images/kc_default_roles_2.png?fit=max&auto=format&n=_0MqQ39OoYOKQTk5&q=85&s=5f12d6b3be1fe4a2f842393974c6783a" alt="" width="1922" height="795" data-path="images/kc_default_roles_2.png" />
   </Frame>

6. If necessary, open the filter dropdown menu and select **Filter by clients**.

7. Select available roles to assign to newly created or imported users.

8. Click **Assign**.

### Group roles

Any permissions that can be granted to an individual by assigning them a role can also be granted to multiple people by assigning the role to a group. This is exceptionally useful for Anaconda Server implementations that utilize an LDAP or Active Directory server.

To assign roles to a group, complete the following steps:

1. [Log in to the Keycloak administrative console](/docs/psm-on-prem/6.5.3/admin/keycloak_config/user_roles#accessing-the-keycloak-administrative-console).

2. Verify you are working in the dev realm.

3. Select **Groups** from the left-hand navigation.

4. Select the group you want to provide permissions to.

5. Select the **Role mapping** tab.

6. Click **Assign role**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/_0MqQ39OoYOKQTk5/images/kc_group_roles.png?fit=max&auto=format&n=_0MqQ39OoYOKQTk5&q=85&s=9b2ee784215c08c3494ff2f58d0ea021" alt="" width="1922" height="797" data-path="images/kc_group_roles.png" />
   </Frame>

7. If necessary, open the filter dropdown menu and select **Filter by clients**.

8. Select available roles to assign to newly created or imported users.

9. Click **Assign**.

### Setting/updating default groups

Setting default groups will automatically assign group membership to all newly created or imported users.

To set the default groups, complete the following steps:

1. [Log in to the Keycloak administrative console](/docs/psm-on-prem/6.5.3/admin/keycloak_config/user_roles#accessing-the-keycloak-administrative-console).

2. Verify you are in the dev realm.

3. Select **Realm settings** from the left-hand navigation.

4. Select the **User registration** tab.

5. Select the **Default groups** tab.

6. Click **Add groups**.

   <Frame>
     <img src="https://mintcdn.com/anaconda-29683c67/_0MqQ39OoYOKQTk5/images/kc_default_groups_2.png?fit=max&auto=format&n=_0MqQ39OoYOKQTk5&q=85&s=d72b6b2385f19297ae5d7973a7afb20c" alt="" width="1922" height="732" data-path="images/kc_default_groups_2.png" />
   </Frame>

7. Select the groups you want to assigned as default.

8. Click **Add**.
