> ## Documentation Index
> Fetch the complete documentation index at: https://bloodhound.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Administer Users and Roles

<img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=ad49a576589f4d2a8081df77d07fdf56" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

## Purpose

This article provides a summary of assignable roles that are available when creating new users in BloodHound.

## Creating users

Users are created through **Settings <Icon icon="gear" iconType="solid" />** <Icon icon="arrow-right" iconType="solid" /> **Administration <Icon icon="arrow-right" iconType="solid" />** **Manage Users**, and clicking the button **Create User**.

The following properties must be set on each user:

| **Property**          | **Description**                                                                                                                                                                                                                                                                                                                                                       |
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Email Address         | Text field for the user's email address.                                                                                                                                                                                                                                                                                                                              |
| Principal Name        | Text field for the username used for logging into BloodHound. Can be the same as email address.                                                                                                                                                                                                                                                                       |
| First Name            | Text field for the user's first name.                                                                                                                                                                                                                                                                                                                                 |
| Last Name             | Text field for the user's first name.                                                                                                                                                                                                                                                                                                                                 |
| Authentication Method | Drop-down selection for one of the available authentication methods to be used for the user.<br /><br />\* Username / Password - Built-in authentication via username and password, supports TOTP-based multifactor authentication.<br />\* SAML - SAML 2.0-based Single-Sign-On as described in [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml).<br /> |
| Initial Password      | Text field for the user's initial password.                                                                                                                                                                                                                                                                                                                           |
| Force Password Reset? | Selecting this check box forces the user to reset their password on the next logon. Must comply with password requirements:<br /><br />\* At least 12 characters long<br />\* Contain at least 1 lowercase character, 1 uppercase character, 1 number and 1 special character (!@#\$%^&\*)                                                                            |
| Role                  | Drop-down selection for one the available roles.                                                                                                                                                                                                                                                                                                                      |

## User Role Definitions

BloodHound offers multiple roles for access control. Each user must be assigned one role.

In BloodHound Enterprise, [Environment Targeted Access Control (ETAC)](/manage-bloodhound/auth/environment-targeted-access-control) can further limit which environments **User** and **Read-only** roles can access. ETAC does not change the baseline permissions in the role matrix below. Instead, it limits which environments those permissions apply to.

For OpenGraph extensions, BloodHound separates read and write permissions. Users without permission to upload or delete extension schemas can still view extension content that their role allows, but the **Upload** and **Delete** extension buttons remain disabled.

<Tip>
  Scroll right to view the full table of permissions for each role.
</Tip>

|                                                                                             |                       **Administrator**                       |                         **Power User**                        |                          **Auditor**                          |                            **User**                           |                         **Read-only**                         |                        **Upload-only**                        |
| ------------------------------------------------------------------------------------------- | :-----------------------------------------------------------: | :-----------------------------------------------------------: | :-----------------------------------------------------------: | :-----------------------------------------------------------: | :-----------------------------------------------------------: | :-----------------------------------------------------------: |
| **Tenant Administration**                                                                   |                                                               |                                                               |                                                               |                                                               |                                                               |                                                               |
| Add, Remove, Modify users                                                                   | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| View users                                                                                  | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| Add, Remove all API keys                                                                    | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| View all API keys                                                                           | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| Add, Remove, View owned API keys                                                            | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |
| Add, Remove SAML provider configurations                                                    | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| View SAML provider configurations                                                           | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| Clear the BloodHound database                                                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| View audit log                                                                              | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| Configure ETAC settings \[BHE]                                                              | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| Upload and delete OpenGraph extension schemas                                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |                               -                               |
| View OpenGraph extensions, findings, and edges                                              | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |
| **Attack Path Analysis**                                                                    |                                                               |                                                               |                                                               |                                                               |                                                               |                                                               |
| View any available tenant data, including active Attack Paths \[BHE], and explore the Graph | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |
| Create, Edit, Delete, Share owned Saved Cypher Queries                                      | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |
| Accept Attack Path Impacted Principals \[BHE]                                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| Modify Tier Zero / High-Value Members                                                       | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| Add, Edit, Remove Privilege Zones, Labels, and Selectors                                    | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| Approve and Revoke certification of Privilege Zone members                                  | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| View, Search, and Filter Privilege Zones Certification Queue                                | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| View, Search, and Filter Privilege Zones History Log                                        | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |
| **Collector Clients and File Ingest**                                                       |                                                               |                                                               |                                                               |                                                               |                                                               |                                                               |
| Download collector installation packages                                                    | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |
| View collector client details \[BHE]                                                        | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |
| View and Filter Finished Jobs Log and job details panel                                     | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |
| Run collector client on-demand scan \[BHE]                                                  | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| Add, modify, and remove a collector client \[BHE]                                           | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| Regenerate collector client credentials \[BHE]                                              | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               |                               -                               |
| File Ingest                                                                                 | <Icon icon="square-check" iconType="solid" color="#22c55e" /> | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |                               -                               |                               -                               |                               -                               | <Icon icon="square-check" iconType="solid" color="#22c55e" /> |
