# Roles and permissions

Zild Admin centralizes users, groups, roles, and permission scope so each person can access only the apps, data, and actions required for their work.

Source: https://zild.ai/en-US/docs/platform/roles-permissions

Zild Admin centralizes users, groups, roles, and permission scope so each person can access only the apps, data, and actions required for their work.

## Access structure



<table class="api-params"><thead><tr><th>Element</th><th>Use</th></tr></thead><tbody><tr><td>User</td><td>Identity associated with a tenant, groups, a primary role, and an operational profile.</td></tr><tr><td>Group</td><td>Organizes users by team, operation, business unit, or another customer-defined structure.</td></tr><tr><td>Role</td><td>Provides a consistent baseline of permissions for administrators, supervisors, and users.</td></tr><tr><td>Effective permissions</td><td>Combines tenant, group, role, and additional scope before an operation is authorized.</td></tr></tbody></table>



## Standard roles

- Administrator: manages platform settings, users, groups, roles, connections, agents, and integrations.
- Supervisor: monitors teams, queues, indicators, and activities within an assigned operational scope.
- User: accesses the operational capabilities required to perform assigned work.

## Permission principles

Apply least privilege, tenant segregation, separation of responsibilities, and periodic access review. Deactivate identities that no longer need access and verify group or role changes before they reach production operations.
