> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management.md).

# Roles management

You can assign the following permissions to various components in Cortex:

| Permission | Description                                    |
| ---------- | ---------------------------------------------- |
| None       | No access to the specified component.          |
| View       | View, but cannot edit the specified component. |
| View/Edit  | View and edit the specified component.         |

**Out-of-the-box roles**

Cortex products include several out-of-the-box roles, such as:

| Role                   | Type       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------------- | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Admin          | Predefined | <p>A super user role that is assigned directly to the user in Cortex Gateway or tenant and has full access to all Cortex products in your account, including all tenants added in the future. In Cortex Gateway, the Account Admin can assign roles for Cortex instances, and can also activate Cortex tenants specific to the product. This user has the same view/edit permissions in the tenant as the Instance Administrator.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The user who activated the Cortex product is assigned the Account Admin role.</p><p>You can add the role to a user in Cortex Gateway or the tenant. You can only remove the Account Admin role from a user in Cortex Gateway.</p><p>Only users with the Account Admin role can add or remove another Account Admin user role.</p></div><p>You cannot edit this role. You can copy the role by saving it as a new role and then changing permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Instance Administrator | Predefined | <p>View/edit permissions for all components and access to all pages in the Cortex tenant. The Instance Administrator can also assign the Instance Administrator role to other users on the tenant. If the application has predefined or custom roles, the Instance Administrator can assign those roles to other users.</p><p>You cannot edit this role. You can copy the role by saving it as a new role and then changing permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Viewer                 | Predefined | <p>Read permissions for all components and pages in the Cortex tenant.</p><p>Cortex AgentiX products comes out-of-the-box with the following Viewer roles:</p><ul><li><p><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABEAAAAQCAIAAAB/UwMIAAAACXBIWXMAABYlAAAWJQFJUiTwAAAAB3RJTUUH6AIUCBIM7CnNpwAAAnJJREFUKJFlks1KMmEYhp8ZX40ZUoTRFBfmX6KiEmILN6ZSR9Bm1h6GGxfiAUgnEUbQSrOdQRvNVUMFFqFWOOPPTAM6OqOvLfwo8btWz+K6ee7FTaxWK9hAkiSz2cxx3M3NzXK5NBgMLpcrmUwyDPPrEJuZWq328PDAsqwgCN/f37IsS5I0Ho/n87ler8/lctuZfD6PMQ6FQpqmuVwuURQVRSEIAmNMUVSz2SRJslAoAAC5DhQKBU3T4vE4AGialkwmY7FYMBh0OBw0TRMEUSwWF4tFqVQCAAQAHMfJspxKpRRFMRqNh4eH5XJ5NBoRBGG3230+3+XlpSRJLMve3t6+vb0hALi+vqYoKp1OX11dhcPhu7s7hNDp6SnG+OvrKxwOq6par9ftdrter39+fkYAMJvNnE5nt9v1+XwcxyGEstnsurPf7weAWCz2+PjYaDSCwWC73SYBQFVVt9s9Ho8tFosgCCcnJ/AfTqeT47herzeZTBAAWK1Wv9+/v78PAG63e8v+/Py8uLjweDyz2UyW5cViQQLA7u7ucDhcGwghhNBmptlsOhwOURQxxhjj1WpFbO1gk8FgcH9/3263WZat1WqCIFAUZTAYyC3v/Pyc5/n1bbVap9Mpy7KtVqvf7wcCAYZhzs7O/v48PT2FQqFKpdJoNEwmk81mi0ajnU6n2+3Ksmw2mw8ODvb29iKRyF91nuff39+Pjo4CgUC1Wu10OjRNv76+KopC07ROp6NpOhKJ/NvBmnQ6/fLyUi6XVVW12WzHx8ckSfI8P5/PRVE0mUyJRGJ7o2s+Pj4qlYogCMvlEgB2dnYYhslkMl6v99f5AcRQMUnIUH9eAAAAAElFTkSuQmCC" alt="gateway-analyst.png"> Viewer role created in Cortex Gateway.</p><p>This role applies to all tenants.</p><p>In the Cortex AgentiX tenant, you cannot edit this role, apart from changing advanced settings such as default dashboards.</p><p>In Cortex Gateway, you can change permissions, apart from advanced settings. You can also delete the role (if not assigned to a user).</p></li><li><p><img src="/files/XbCr7IHISPLmX8eogI3t" alt="tenant-analyst.png"> Viewer role created in the tenant.</p><p>This role is specific to the tenant. You can edit all permissions and delete the role (if not assigned to a user) in the tenant.</p></li></ul><p><img src="https://ci3.googleusercontent.com/meips/ADKq_NYdAynQWMXbu-X0m09lI7lTcrlA-lVPgep5L-bfbNAD3vYm2qzq9aPpAhSJk0k3l0Nr8ePgAPcIR6TWsE0vJEdSoM4Fc5kf5UfnHUOrq_Y3q1sWDtIsAuo1q2nou-DVZ8BZKVTCuG2T4MBrcqWQExrR_fW_75_fcd2NQ_4JQ7G0p_VNk20c-MtRi7270po_cyCa=s0-d-e1-ft#https://paloaltonetworks.paligoapp.com/usr/paloaltonetworks/media/0c2b1730e3655b4b1d720a1d3fbac001/937802_spr.png?1708417250" alt="" data-size="original"></p> |

{% hint style="info" %}

### Note

By default, users do not have roles assigned. If no direct or user group role has been assigned, users don't have permission to view or edit data in the Cortex tenant.
{% endhint %}

**Next steps**

Before you start creating or customizing roles, do the following:

* Review the Role-based permissions topic.
* Decide where you want to create roles (Cortex Gateway, the tenant, or both).

  Any roles and user groups created in Cortex Gateway are available for all tenants. In the Cortex tenant, all roles created in the tenant are specific to the tenant. Advanced settings such as default dashboards/queries and shifts can only be defined at the tenant level. Only user groups created on the tenant can be mapped to SAML groups when using SAML SSO.
* Decide whether you want to assign roles to users directly or through membership in user groups (recommended) in Cortex Gateway or the Cortex tenant.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
