A role is defined as a group of actions that a user is allowed to perform within a given domain. Roles determine the user's authorized activities, ensuring the users have access to only the functions necessary to complete their particular operational responsibilities.
Trellix IPS implements role-based authorization, wherein users can perform only those activities permitted by their role. Roles are always domain based, that is, a role governs what activities a user can perform within a particular domain. Users never have roles that are not tied to managing a resource within a specific domain and its children, although users can exist in the database without being assigned a role.
Roles promote the integrity of security configuration by not allowing universal access to every security resource deployed in the system. Thus you can create a user with privileges to manage and configure a single child domain, perform user management tasks within that domain, generate reports, manage Sensors, and so on. You can assign the least privileges necessary for a user to perform his/her specific job function, and no more. The user is limited to the specific role functions within the assigned child domain and its children, and prevents the user from manipulating other domains.
For example, only the Root Admin Domain System Administrator sees the Manager. System Administrators without privileges at the Root Admin Domain level are allowed to configure and maintain their child domains within the system, but do not see the Manager.
Note
The Root Admin Domain Super User is able to override the roles of any user.