> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management.md).

# Roles management

You can assign the following permissions to various components in Cortex XSOAR:

| Permission | Description                                 |
| ---------- | ------------------------------------------- |
| None       | No access to the specified component.       |
| View       | View, but not edit the specified component. |
| View/Edit  | View and edit the specified component.      |

#### Out-of-the-box roles

Cortex XSOAR includes the following out-of-the-box roles:

| Role                   | Type       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ---------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Account Admin          | Predefined | <p>The user who supplied their credentials when installing Cortex XSOAR is assigned the Account Admin role. This user has view/edit permissions for all components and access to all pages in the Cortex XSOAR tenant (the same view/edit permissions as the Instance Administrator). You cannot create additional Account Admin roles in Cortex XSOAR.</p><p>You cannot edit this role.</p>                                                     |
| Instance Administrator | Predefined | <p>View/edit permissions for all components and access to all pages in the Cortex XSOAR tenant. The Instance Administrator can also assign the Instance Administrator role to other users on the tenant. If the application has predefined or custom roles, the Instance Administrator can assign those roles to other users.</p><p>You cannot edit this role. You can copy the role by saving it as a new role and then change permissions.</p> |
| Analyst                | Custom     | A mix of view and view/edit permissions for all components and access to all pages in the Cortex XSOAR tenant.                                                                                                                                                                                                                                                                                                                                   |
| Read-Only              | Custom     | Read permissions for all components and pages in the Cortex XSOAR tenant.                                                                                                                                                                                                                                                                                                                                                                        |

{% hint style="info" %}

### Note

By default, users do not have roles assigned. If no direct or user group role has been assigned, users have no permission to view or edit data in Cortex XSOAR.
{% endhint %}

#### Next steps

Before you start creating or customizing roles, do the following:

* Review the [Role-based permissions](/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md) topic.
* Decide whether you want to assign roles to users directly or through membership in user groups (recommended) in the Cortex XSOAR tenant.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
