> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding Roles and Permissions

> How the role and module access determine what a user can see and change in Docusnap365.

Two settings determine what a user can see and change in Docusnap365: the
user's role and the *Module Access* per module. The role applies to the whole
subscription; *Module Access* restricts it for individual modules.

## Roles

Every user has exactly one of four roles.

| Role | Permissions |
| - | - |
| *Owner* | All permissions, including billing. Each subscription has exactly one owner. |
| *Administrator* | All permissions, including user management. |
| *Contributor* | Create and edit data in the assigned modules. |
| *Viewer* | Read data in the assigned modules. |

*Owner* and *Administrator* assign and change roles. An administrator cannot
change the owner's role. No user can change their own role.

## Module access

The role sets an access level for every module: *Administrator*,
*Contributor* or *Viewer*. For *Contributor* and *Viewer*, you can reduce this
level per module, down to *No Access*. You cannot raise it; a viewer gets write
permissions in no module. For *Owner* and *Administrator*, every module has the
level *Administrator*.

If at least one module deviates from the role, the user list shows
*Individual* instead of the role.

Modules depend on each other. ITAM works with the assets of the inventory: to
use ITAM fully, the user needs at least the level *Viewer* for Inventory. If
that level is missing, the permission settings show a red warning icon after
*ITAM*.

## Locked modules

A module set to *No Access* is locked for the user. When the user opens it,
the page *No Access to This Area* appears instead of the content. The main menu
and the navigation remain usable. Once an owner or administrator grants the
permission, the module opens at the same address.

The home page and the *Profile Settings* are open to every user, regardless of
role and *Module Access*.

## Reading without write permission

Without write permission in a module, Docusnap365 hides all controls that
change data: editing, adding, actions in lists and edit bars. They are not
shown as disabled, and no message appears. For a viewer, this is the normal
state.

## Administration

*Administration* opens only for *Owner* and *Administrator*. A contributor or
viewer who opens an address in Administration is redirected to the home page;
a message states that the permission is missing and that an administrator can
grant it.

## Related

[Users and Roles](/docs/en/settings/users) describes how to invite users, assign
roles and set *Module Access*. How sign-in and data are protected is described
under [Security](/docs/en/getting-started/security).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.