# Roles

Access in JetBrains Central Console is role-based. Every role is some combination of [permissions](#permissions) that define what this role can do. You can either use [default roles](#default_roles) or create a new one and then assign it to principals: [users](users.html), [groups](groups.html), and [service accounts](service-accounts.html).

> **Note:**
> Managing roles is available only for users with the [Manage organization](#permissions_manage_org) permission.

Procedure: Create roles

1. In the sidebar, under Users and access, select Roles.

If you don't see this page, your role doesn't have the necessary [permissions](#permissions).

2. In the top-right corner of the Roles page, click New role.

3. In the New role dialog, enter a name for the role.

4. Under Scope, select the [scope](#role-scopes) where the permissions of this role should apply: Organization or Groups.

5. Define the set of permissions for this role.

6. Click Create.

Procedure: Edit roles

1. In the sidebar, under Users and access, select Roles.

If you don't see this page, your role doesn't have the necessary [permissions](#permissions).

2. Click the permissions assigned to the role.

Alternatively, click ... next to the role and select Edit role.

3. In the Edit role dialog, edit the permissions and the name of the role.

> **Note:**
> You can't change the [scope](#role-scopes) of a role.

4. Click Save changes to apply.

Procedure: Delete roles

1. In the sidebar, under Users and access, select Roles.

If you don't see this page, your role doesn't have the necessary [permissions](#permissions).

2. Click ... next to the role and select Delete role.

3. Confirm deletion.

Procedure: Assign roles

You can assign roles to [principals](ai-governance.html#principal): users, groups, and service accounts. Assigning a role adds permissions that this role includes.

For information about assigning roles, see:

* [Manage user permissions](users.html#user_permissions)

* [Manage group permissions](groups.html#group_permissions)

* [Manage service account permissions](service-accounts.html#service-account-permissions)

## Permissions

Permissions define which sections of the UI the role has access to.

| Permission | [Users and access](users-and-access.html) | Licensing | Billing | [AI governance](ai-governance.html) | Usage | [Organization](organization.html) |
| [Users](users.html) | [Groups](groups.html) | [Roles](#intro) | [Service accounts](service-accounts.html) | Products and services | Licenses | Teams | Transactions and invoices | Spending report | Subscription packs | [AI access](ai-access.html) | [AI settings](ai-settings.html) | [AI providers](ai-providers.html) | [AI policies](ai-policies.html) | [Agents](ai-agents.html) | [AI analytics](ai-analytics.html) | [Contacts](contacts.html) | [Administration](org-administration.html) |
| [Manage organization](#permissions_manage_org) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) |
| [View organization members](#permissions_view_org) | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [Manage AI settings](#permissions_manage_ai_settings) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [View AI settings](#permissions_view_ai_settings) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [Manage AI access](#permissions_manage_ai_access) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [View AI access](#permissions_view_ai_access) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg)* | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [View AI analytics](#permissions_view_ai_analytics) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [View AI analytics (self)](#permissions_view_ai_analytics_self) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) |
| [Manage licensing and billing](#permissions_manage_licensing_and_billing) | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/cross.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/check.svg) |
| [Manage purchases](#permissions_manage_purchases) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg)* | ![](images/check.svg) | ![](images/check.svg) | ![](images/check.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg)* |
| [View licenses](#permissions_view_licenses) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/check.svg)* | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/cross.svg) | ![](images/check.svg)* |

* Read-only access.

### Manage organization

Allows managing everything in JetBrains Central Console.

Only the [Org admin](#org_admin) has this permission by default.

### View organization members

Allows viewing information about [users](users.html), [groups](users.html), [roles](#intro), and [service accounts](service-accounts.html).

Only the [Org viewer](#org_viewer) has this permission by default.

### Manage AI settings

Allows managing [AI settings](ai-settings.html), [providers](ai-providers.html), [policies](ai-policies.html), and [agents](ai-agents.html).

Only the [AI admin](#ai_admin) has this permission by default.

### View AI settings

Allows viewing [AI settings](ai-settings.html), [providers](ai-providers.html), [policies](ai-policies.html), and [agents](ai-agents.html).

The following [default roles](#default_roles) have this permission by default:

* [Org viewer](#org_viewer)

* [AI viewer](#ai_viewer)

### Manage AI access

Allows managing [AI access](ai-access.html).

Only the [AI admin](#ai_admin) has this permission by default.

### View AI access

Allows viewing [AI access](ai-access.html).

The following [default roles](#default_roles) have this permission by default:

* [Org viewer](#org_viewer)

* [AI viewer](#ai_viewer)

### View AI analytics

Allows viewing [AI analytics](ai-analytics.html).

The following [default roles](#default_roles) have this permission by default:

* [Org viewer](#org_viewer)

* [AI admin](#ai_admin)

* [AI viewer](#ai_viewer)

* [AI analytics viewer](#ai_analytics_viewer)

### View AI analytics (self)

Allows viewing [AI analytics](ai-analytics.html) for the currently logged-in user only. With this permission, the user can access the `Usage | AI analytics` section in JetBrains Central Console and see their own data in analytics charts and tables. This permission doesn't let users see organization-wide, group-level, or other users’ metrics.

View AI analytics (self) is not included in any default role. For a user to access and see their own metrics, a role that includes this permission must be assigned manually to the user or to a group they belong to.

### Manage licensing and billing

Allows purchasing and assigning licenses, managing billing, [teams](about-teams.html), [contacts](contacts.html), and [global org settings](org-administration.html). Also allows viewing information about [users](users.html), [groups](users.html), and [roles](#intro).

Only the [Licensing and billing manager](#licensing-and-billing-manager) has this permission by default.

### Manage purchases

Allows purchasing licenses, managing billing, viewing [teams](about-teams.html) and [global org settings](org-administration.html).

The following [default roles](#default_roles) have this permission by default:

* [Licensing and billing manager](#licensing-and-billing-manager)

* [Purchase manager](#purchase-manager)

### View licenses

Allows viewing licenses, [teams](about-teams.html), and [global org settings](org-administration.html).

The following [default roles](#default_roles) have this permission by default:

* [Org viewer](#org_viewer)

* [Licensing and billing manager](#licensing-and-billing-manager)

* [Purchase manager](#purchase-manager)

* [License viewer](#license-viewer)

Primary contacts have access to your organization's profile and receive [email notifications](contacts.html#email-notifications) relevant to their role.

|  Role  |  Permitted actions  |  Email notifications  |
| --- | --- | --- |
| Primary licensee |      * View all licenses and teams    |  Licensing notifications  |
| Primary technical |      * View all licenses and teams    |  Technical updates  |
| Primary billing |      * View all licenses and teams    * View, edit, and renew subscription packs    * View your organization’s spending report    * View and download all invoices    * Purchase new licenses    |  Billing notifications  |

## Default roles

JetBrains Central Console defines several default roles.

### Org admin

A primary organization admin role with management access to everything.

Default permissions:

* [Manage organization](#permissions_manage_org)

### Org viewer

A role with read-only access to most pages in JetBrains Central Console.

Default permissions:

* [View organization members](#permissions_view_org)

* [View AI settings](#permissions_view_ai_settings)

* [View AI access](#permissions_view_ai_access)

* [View AI analytics](#permissions_view_ai_analytics)

* [View licenses](#permissions_view_licenses)

### AI admin

A role with management access to AI-related pages.

Default permissions:

* [Manage AI settings](#permissions_manage_ai_settings)

* [Manage AI access](#permissions_manage_ai_access)

* [View AI analytics](#permissions_view_ai_analytics)

### AI viewer

A role with read-only access to AI-related pages.

Default permissions:

* [View AI settings](#permissions_view_ai_settings)

* [View AI access](#permissions_view_ai_access)

* [View AI analytics](#permissions_view_ai_analytics)

### AI analytics viewer

A role with access only to AI analytics.

Default permissions:

* [View AI analytics](#permissions_view_ai_analytics)

### Licensing and billing manager

A role with management access to licensing and billing – not only purchasing licenses but also assigning them.

Default permissions:

* [Manage licensing and billing](#permissions_manage_licensing_and_billing)

* [Manage purchases](#permissions_manage_purchases)

* [View licenses](#permissions_view_licenses)

### Purchase manager

A role for license procurement – purchasing licenses but not assigning them.

Default permissions:

* [Manage purchases](#permissions_manage_purchases)

* [View licenses](#permissions_view_licenses)

### License viewer

A role for read-only billing oversight.

Default permissions:

* [View licenses](#permissions_view_licenses)

## Role scopes

Every role has a scope that determines where its permissions apply.

* Organization for roles with permissions that should apply across the entire organization.

* Groups for roles with permissions that should apply only within a specific [group](groups.html). For example, a team lead can have group-scoped permissions to manage AI access for their group's members only.

> **Note:**
> You can only define the scope when creating a role. If you need to change the scope, create a new role.

Not all permissions support group scopes. A role scoped to groups can only have the following permissions:

* [Manage AI access](#permissions_manage_ai_access)

* [View AI access](#permissions_view_ai_access)

* [View AI analytics](#permissions_view_ai_analytics)

## Team admin

This is a special role for users who manage licenses and orders within a [team](about-teams.html). Team admins don't have visibility into or control over other teams or organization-wide settings.

Team admins can:

* Assign and revoke licenses from the team's pool.

* Purchase or upgrade licenses for the team.

* Invite other team admins to manage the same team.

You can get the team admin role automatically when purchasing licenses or by invitation from an org admin or another team admin.

* Purchasing new licenses does not grant you the org admin role for an existing organization if another person previously purchased licenses for that organization. Instead, your purchased licenses will form a new team, and you will receive the team admin role.

* Org admins and team admins can invite you to become a team admin for a specific team. For more information, see [Add or remove team admins](add-or-remove-team-admins.html).

## See also

### Concepts

[Users](users.html) [Groups](groups.html) [Service accounts](service-accounts.html)

### Learn how to

[Add or remove team admins](add-or-remove-team-admins.html)

