It is important to understand the relationship between parent and child admin domains because (by default) child admin domains inherit policies from parent admin domains, and because users are automatically granted the same privileges in the child domains as those enabled by their roles in the parent domain.
Policy inheritance means that a child takes policies, or inherits them, from the parent. If you do not specify a policy when you create the child, the child automatically inherits the policies of its parent. To override policy inheritance from parent, you assign a policy to the child admin domain that is specific to that child domain.
For more information on policies, see Working with IPS policies.
User roles work similarly, but with a slight difference. Roles apply within the current domain and any of its children. Because child domains are essentially contained within parent domains, if a user is given, for example, a Super User role for a parent domain, that role also applies to all children of the parent. Thus, to use the domain hierarchy shown in the figure in Admin domain hierarchy as an example, a user assigned a System Administrator role for the Finance department has that role for the Payroll and Accounts Payable domains as well.
Note that additional roles can be granted to the user at the child level, but a role granted at a parent cannot be overridden at a child level.
For more information on roles, see Management of users and user roles.