Roles

Assign roles to a profile to determine the actions that a user can perform.

Using roles

Some roles, such as System Administrator, Company Administrator, User) can be used by themselves. Other roles are used as "building blocks" and are used in combination to grant permissions to accounts and resources.

Role descriptions

TypeValue
AdministratorThis role can administer user accounts for its own tenant only. It cannot create a new tenant.  
Business Rules - full accessThis role has all permissions (view, modify, import, export) for business rules for its own tenant. A user must be assigned the BusinessRule - full or the BusinessRule - view only role to run HIPAA Type 6 and Type 7 transactions. 
Business Rules - view onlyThis role can view business rules for its own tenant. A user must be assigned the BusinessRule - full or the BusinessRule - view only role to run HIPAA Type 6 and Type 7 transactions. 
Code Lists - full accessThis role has all permissions for code lists (view, modify) for its tenant. 
Code Lists - view onlyThis role can view code lists for its tenant. 
Company AdministratorThis role can administer passwords, add users, manage resources, and perform most other functions for its own tenant only. This role can also view the profile information of other users. The Company Administrator role cannot create a new tenant.  
ControlNumbers - full accessThis role has all permissions (view, modify) for control numbers for its tenant. 
ControlNumbers - view onlyThis role can view control numbers for its tenant. 
DefaultThis role has a minimum set of permissions and can log in only. 
Envelopes - full accessThis role has all permissions (view, modify) for envelopes for its tenant. 
Envelopes - view onlyThis role can view envelopes for its tenant. 
ExportThis role can export resources for its tenant. 
ImportThis role can import resources for its tenant. 
Maps - full accessThis role has all permissions (view, modify) for maps for its tenant. 
Maps - view onlyThis role can view maps for its tenant. 
RESTThis role can submit REST API jobs for its tenant. A user with the role cannot view or access the REST jobs of another user. 
Schemas - full accessThis role has all permissions (view, modify) for schemas for its tenant. 
Schemas - view onlyThis role can view schemas for its tenant. 
System AdministratorThis role can manage users and resources across all tenants. This role is available for the default when SPE is installed. 
UserThis role can manage resources for its tenant.