---
title: Users
slug: litmusedge-v1/product-features/system/users
description: The Users pane allows you to add and manage permissions for your edge device's users. 
docTags: 
createdAt: 2022-05-13T18:57:11.000Z
---

The *Users* pane allows you to add and manage permissions for your edge device's users.&#x20;

# Relationship of Roles, Groups, and Users

:::hint{type="info"}
**Note**: Role-based access control (RBAC) is available for Litmus Edge version 3.3.1 and later.&#x20;
:::

Litmus Edge incorporates a Role-based access control (RBAC) to customize user permission settings in the form of three distinct components.

- **Roles**: Each role has a collection of customizable permissions. Roles are added to groups and determine the permissions groups have. See [Role Permissions](docId\:uO7n5qVXgtE412BQNFzUT) for details.&#x20;
- **Groups**: A group is made up of one or more roles. The roles in a group determine the permissions for the group.&#x20;
- **Users**: Accounts that will be assigned to groups. The one or more groups a user is assigned to determines the roles and permissions the user has.

Working together, a *Role&#x20;*&#x64;etermines the permission settings a *Group&#x20;*&#x77;ill have. A *Group&#x20;*&#x77;ill contain one or more roles that determines its permissions. A *User&#x20;*&#x77;ill be assigned to a *Group&#x20;*&#x77;here it will have access to Litmus Edge based on the the Group's one or more *Roles*.

:::hint{type="warning"}
**Important**: The following properties should be kept in mind when adding/editing Roles/Groups/Users.

- A group can receive more than one role (and their respective permission settings) to a resource.
- A user can be assigned to multiple groups.
- If a user is not assigned to at least one group, they will not be able to log in to Litmus Edge.&#x20;
- In the case of conflicting permission settings: As long as there is at least one role or group with permissions to a resource, regardless of how many other roles/groups that don't have it, users will receive that resource.
:::

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/5kJHdGV18bL1-3UvqROP6_image.png" size="80" width="804" height="322" caption="Visual representation of roles, groups, and users" position="center" showCaption="true"}

# Default Roles, Groups, and Users

By default, the following user management items are provisioned that can't be deleted.&#x20;

**Roles**

- Administrator
- Viewer

**Groups**

- Administrators
- Viewers

**User**

- admin

The system ensures that at least one user has the appropriate administrative permissions to manage roles, groups, and users.&#x20;

# Default User Permissions

By default, every user has the permission to accept the Litmus Edge end-user license (EULA) when logging in the first time. Users can also access their user profile to view their current user permissions and change their password. See [Manage Your User Profile](docId\:gTmD3l5p8vWEeCUwl21tx) for details.&#x20;

Every user also has the *View&#x20;*&#x70;ermission for the following components when navigating to the *System&#x20;*&#x6D;odule in Litmus Edge.&#x20;

- Info
- Certificates
- Network
- Remote Access
- Device Management
- Services
- External Storage
- Policy Management
- License
- Support&#x20;

Learn more about [Role Permissions](docId\:uO7n5qVXgtE412BQNFzUT).&#x20;

# Backup Files and Templates

All role, group, and user configurations are included in backup files. See [Backup/Restore](docId\:Q_mfOXtLO2fAHvHW1JcEf) and [Backup File Contents and File Management](docId\:q6Abk1gtv_I0EILNedOk_) for more information.&#x20;

In template files, only authentication providers are included in template configurations. If you apply a template to a new edge device, you will need to map LDAP groups manually. See [Manage LDAP Providers](docId\:wgRdPfo4Si0EboUPRwv11) for more information.&#x20;

# Legacy User Migration

For Litmus Edge instances on version 3.2 and earlier, there were three possible roles: Observer, Developer, and Administrator. When you upgrade to version 3.3 or later:

- Any Administrator role is automatically provisioned to the Administrators group with the group's respective permissions.&#x20;
- Observer and Developer roles are automatically provisioned to the Viewers group with the group's respective permissions.&#x20;

# Access Users UI

:::hint{type="info"}
**Note**: You must have the appropriate permissions to manage roles, groups, and users. By default, the first user (admin user) provisioned in Litmus Edge has these user permissions.&#x20;
:::

**To access the Users UI:**

1. Log in to Litmus Edge.
2. From the Navigation panel, navigate to **System&#x20;**> **Users**.
   The *Users&#x20;*&#x70;ane appears. The *Roles&#x20;*&#x74;ab displays by default. You can switch to the *Groups&#x20;*&#x61;nd *Users&#x20;*&#x74;abs.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/5EKyNX1Nj-D3qsR-7rNMO_usersui.png "The Users pane")

# Next Steps

- [Add a Role](docId\:dazL05SzpwAIghSGgzGWm)&#x20;
- [Manage Roles](docId\:eF9lAFXybKEEz_TeXkouB)&#x20;
- [Add a Group](docId\:Mw1LRjWoqzQc9lMW-e4L6)&#x20;
- [Manage Groups](docId\:w7_PXV1hJT6PFuD69xZuG)&#x20;
- [Add a User](docId\:ZAQkctsyRM2oGPIiSvwY9)&#x20;
- [Manage Users](docId\:jrIuN6tXa-Awv1mJZPmqz)&#x20;
- [Manage Your User Profile](docId\:gTmD3l5p8vWEeCUwl21tx)&#x20;
- [Role Permissions](docId\:uO7n5qVXgtE412BQNFzUT)&#x20;

