Role Based Key Management enables a Global Key Administrator to define roles and assign them to permission sets. Users can manage only the keys for the roles contained in the respective permission set.
Role of the Global Key Administrator
In addition to creating users and permissions sets, the Global Key Administrator (GKA) is responsible for creating roles and assigning the roles to user's permission sets appropriately. The GKA is assigned the Default role.
The Default role is created automatically and cannot be deleted. It enables the GKA to manage roles throughout the system. The GKA can manage only keys for the Default role. Keys associated with other roles are not accessible to the GKA. Those keys are managed by ePO - On-prem admin users based on their role assignments, meaning that they can manage only the keys associated with their roles.
Roles and permission sets
A permission set can contain any number of roles. A user or administrator can manage only the keys for the roles contained in the respective permission set.
If a user has more than one assigned permission set, that user receives the roles assigned in all of the permission sets upon log in with their respective Key Server settings. If the user has View Key Server permissions for a role in one permission set, and Manage Key Server permissions for the same role in a different permission set, the Manage Key Server permission setting is applied for that role.