> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/learn-more/administration/admin-roles/permissions-matrices.md).

# Permissions Matrices

Permissions in the matrices below are grouped into what product areas or functions they relate to. If a role type is not included in the table, it has no permissions related to that area.

:mouse\_three\_button:View in full screen, or scroll right within the table to view all role&#x73;**.**

{% hint style="warning" %}
Global role permissions apply to all tenants. Tenant role permissions apply only to the tenant the user is assigned the role in. Users can't have more than one tenant role. If a user needs permissions on more than one tenant, assign a Global role.

Tenant roles are indicated with \* . For example, Tenant Admin\*

[Learn more here.](/learn-more/administration/admin-roles.md#h-role-descriptions)
{% endhint %}

## Detections

{% hint style="success" %}
All Roles can **view** detections
{% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Analyst</th><th>Analyst*</th></tr></thead><tbody><tr><td><p>Update Material <a href="/pages/iAXbqBgtoXW0IuTgdxpx">detections</a><br></p><ul><li>Enable/disable</li><li>Change severity</li><li>Configure response</li><li><a data-footnote-ref href="#user-content-fn-1">Reset circuit breaker</a></li></ul></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Create, update, and archive <a href="/pages/1WcriMWZO5Y0zVHehkjv">custom detections</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## Issues

<table data-full-width="true"><thead><tr><th width="168.265625"></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Phishing Simulation Admin</th><th>Phishing Simulation Admin*</th><th>Global Settings Admin</th><th>Settings Admin*</th><th>Global Issue Responder</th><th>Issue Responder*</th></tr></thead><tbody><tr><td>View all issues and <a data-footnote-ref href="#user-content-fn-2">evidence</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><p>Update issues:</p><ul><li>update <a href="/pages/YzhvthXd8qXot5RCAJWA#filter-definitions">status</a></li><li><a href="/pages/d03fYxKEQziYWTYr1NXs">assign to a user</a></li><li><a href="/pages/Kp95qzb1fOhLr2B2Ylk9">manually respond</a></li></ul></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/laPR5xHE28DMjkrhiav8#share-issues">Share issue feedback</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-3">View message content (associated with an <strong>issue only</strong></a>)</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-4">Delete messages (associated with an <strong>issue only</strong></a>)</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-5">View file content (associated with an <strong>issue only</strong></a>)</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/Kp95qzb1fOhLr2B2Ylk9">Manually respond to an issue</a></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr></tbody></table>

## Entity Specific Permissions

These permissions related to specific entity types within issues.

### Messages

<table data-full-width="true"><thead><tr><th width="161.50390625"></th><th>Super Admin</th><th>Tenant Admin*</th><th width="141.15234375">Content Admin*</th><th width="184.71484375">Email Content Admin*</th><th>Global Analyst</th><th>Analyst*</th><th width="128">eDiscovery Admin</th><th>Global Issue Responder</th><th>Issue Responder*</th></tr></thead><tbody><tr><td><a href="/pages/CdUDVYLLRQg3mQK9EFuJ">Search</a> and view all messages, (including metadata <strong>and</strong> content)</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td><a href="/pages/CdUDVYLLRQg3mQK9EFuJ">Search</a> and view all messages, (<strong>metadata only</strong>)</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-6">View <strong>all</strong> message content</a></td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-3">View message content (associated with an <strong>issue only</strong></a>)</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-7">Delete <strong>any</strong> messages</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-4">Delete messages (associated with an <strong>issue only</strong></a>)</td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Create an Email Threat issue from a message manually</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td></tr><tr><td><a href="/pages/Snr49rN3vQaOkll6gmPx#step-two-force-unlocks">Force Unlock Messages</a></td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td><a href="/pages/YzhvthXd8qXot5RCAJWA#copy-issue-id">Share message content with Material</a></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td>✔️</td><td>✔️</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-8">Mark messages as sensitive</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-9">View message header explanations</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr></tbody></table>

### Sensitive Categories

{% hint style="success" %}
All roles can **view** sensitive categories.
{% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Content Admin*</th><th>Email Content Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Settings Admin</th><th>Settings Admin*</th></tr></thead><tbody><tr><td>Create, edit, and archive <a href="/pages/zh2CSAAQu2OP9atfJeT2">Sensitive categories</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>Update default response</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr></tbody></table>

### Files

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Content Admin*</th><th width="146.046875">Drive Content Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>eDiscovery Admin</th><th>Global Issue Responder</th><th>Issue Responder*</th></tr></thead><tbody><tr><td><a href="/pages/GeOgwNROCDpxbucEHg1X">Export .csv in the Explorer for files</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>Search files (metadata <strong>and</strong> content)</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td>Search files (<strong>metadata only</strong>)</td><td>✔️</td><td>✔️</td><td>​</td><td>​</td><td></td><td></td><td>​</td><td></td><td></td></tr><tr><td><a href="/pages/Kp95qzb1fOhLr2B2Ylk9">Manually respond to an issue related to a file</a></td><td>✔️</td><td>✔️</td><td>​✔️</td><td>​✔️</td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td>View file metadata</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>View <strong>all</strong> file content</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Update file sharing permissions</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update file labels</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td><td></td><td></td><td></td></tr></tbody></table>

***

## Stats and Reports

{% hint style="success" %}
All roles **except** Tenant Enroller, Global Settings Admin, and Settings Admin can:

* Views stats on the counts of issues throughout the app
* View issue reports
* View message reports

All roles **except** Tenant Enroller, Global Issue Responder, and Issue Responder can:

* View the Usage Report
  {% endhint %}

***

## Settings

{% hint style="success" %}
All roles can:

* **View** account settings for the account they're logged in with
* **View** Email Threat settings
* **View** Google Drive settings
* **View** Account Takeover Resilience (ATO) settings
* **View** organizational profile settings
* **View** end-user support settings
* **View** admin console settings (excluding SSO SAML)
* **View** SAML SSO (all except Tenant Enroller can view)
* **View** outbound IP settings
* **View** Outlook add-in settings
* **View** Mailbox Mirroring settings
* **View** end-user verification settings (all except Tenant Enroller can view)
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Settings Admin</th><th>Settings Admin*</th></tr></thead><tbody><tr><td>Update account settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update <a href="/pages/QFXz1gpqgipPRC2VmBf8">Email Threat settings</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Update Google Drive settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update<a href="/pages/7bZYRAOFF6SojietmPTt"> ATOR settings</a></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update Organizational Profile settings (excluding VIP Designation)</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update end-user support settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>View, add, and update <a href="/pages/ozcxVXkcpXTHCc1rHnyY">Trusted Entities</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Update admin console settings, including SAML SSO</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Update end user verification settings (excluding challenge bypass)</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Create/update/delete a challenge bypass</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td></tr><tr><td>Update Outlook add-in settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## Accounts and Groups

{% hint style="success" %}
All roles can:

* **View** account and group details
* [Re-sync group members](/getting-started/fundamentals/explore/re-sync-a-group.md)
* **View** tenants
* **View** detected apps
* [Export a .csv](/getting-started/fundamentals/explore/export-a-.csv-in-the-explorer.md) in the Explorer for accounts and groups.
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Settings Admin</th><th>Settings Admin*</th></tr></thead><tbody><tr><td>Enroll new tenants</td><td>✔️</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Update account settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Assign and revoke <strong>all</strong> role types for other users</td><td>✔️</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Assign and revoke all roles to accounts <strong>excluding super admin and tenant enroller</strong></td><td></td><td>✔️</td><td></td><td></td><td></td><td></td></tr><tr><td>Revoke session for account</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>Update group settings</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Assign and revoke <strong>all</strong> role types for groups</td><td>✔️</td><td></td><td></td><td></td><td></td><td></td></tr><tr><td>Assign/revoke roles to groups <strong>excluding super admin and tenant enroller</strong></td><td></td><td>✔️</td><td></td><td></td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-10">Update Material delegates</a></td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## Tenants

{% hint style="success" %}
All roles can:

* **View** tenants
* [Export a .csv](/getting-started/fundamentals/explore/export-a-.csv-in-the-explorer.md) in the Explorer for tenants.
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Enroller*</th></tr></thead><tbody><tr><td>Enroll new tenants</td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## Phishing Simulations

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Phishing Simulation Admin</th><th>Phishing Simulation Admin*</th></tr></thead><tbody><tr><td>View Phishing simulations in a <a data-footnote-ref href="#user-content-fn-11">dedicated</a> <strong>or</strong> <a data-footnote-ref href="#user-content-fn-12">shared</a> instance</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td></tr><tr><td>Create and update simulations in a <a data-footnote-ref href="#user-content-fn-11">dedicated</a> <strong>or</strong> <a data-footnote-ref href="#user-content-fn-12">shared</a> instance</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td></tr><tr><td>View Phishing simulations in a <a data-footnote-ref href="#user-content-fn-13">shared</a> instance, assign to one tenant</td><td>✔️</td><td>✔️</td><td></td><td>✔️</td></tr><tr><td>Create and update simulations in a <a data-footnote-ref href="#user-content-fn-13">shared</a> instance, assign to one tenant</td><td>✔️</td><td>✔️</td><td></td><td>✔️</td></tr></tbody></table>

***

## OAuth Apps

{% hint style="success" %}
All roles can:

* **View** connected OAuth apps
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Phishing Simulation Admin</th><th>Phishing Simulation Admin*</th><th>Global Settings Admin</th><th>Settings Admin*</th></tr></thead><tbody><tr><td>View OAuth issues</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>Classify apps and add responses</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td></tr><tr><td>Configure OAuth settings (auto-remediation, responses)</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td>✔️</td><td>✔️</td></tr><tr><td>Configure OAuth notifications</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td></tr></tbody></table>

***

## Audit Log

{% hint style="success" %}
All roles can:

* **View** audit logs for the account they are logged in with
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Content Admin*</th><th>Email Content Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>eDiscovery Admin</th><th>Global Issue Responder</th><th>Issue Responder</th></tr></thead><tbody><tr><td>View <a data-footnote-ref href="#user-content-fn-14">audit log</a> entries</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td></td><td></td></tr><tr><td>View message access log</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>View force unlock requests</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td>✔️</td><td></td><td></td></tr></tbody></table>

## Integrations

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Content Admin*</th><th>Global Analyst</th><th>Analyst*</th><th>Global Analytics Admin</th><th>Analytics Admin*</th><th>Global Settings Admin</th><th>Settings Admin*</th></tr></thead><tbody><tr><td>View integrations</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Create and modify integrations</td><td>✔️</td><td>✔️</td><td></td><td></td><td></td><td></td><td></td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## Event Subscriptions

{% hint style="success" %}
All roles can:

* **View** event subscriptions
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th></tr></thead><tbody><tr><td>Create and modify event subscriptions</td><td>✔️</td><td>✔️</td></tr></tbody></table>

***

## APIs and MCP

{% hint style="success" %}
All roles can:

* **View** API tokens
* **Create and modify API tokens** for the account they are logged in with
  {% endhint %}

<table data-full-width="true"><thead><tr><th></th><th>Super Admin</th><th>Tenant Admin*</th><th>Global Settings Admin</th><th>Settings Admin</th></tr></thead><tbody><tr><td>Create and modify <strong>all</strong> API tokens</td><td>✔️</td><td>✔️</td><td></td><td></td></tr><tr><td>Modify settings to allow API token creation</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td>Enable the Material MCP server</td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr></tbody></table>

`*` : [Tenant role](https://docs.material.security/learn-more/administration/admin-roles/pages/6MBgSXCT0ViAaChZeq8h#tenant-roles-vs.-global-roles)

[^1]: If the detection triggered too many items in a short period of time indicating it might be misconfigured it is automatically disables. For custom detections only, the admin can re-enable it via an event subscription.

    See the Events documentation in the admin console for Detection/Custom Detection Disabled.

[^2]: including metadata and details

[^3]: To view all messages including those not associated with an issue, see the **Messages** table below

[^4]: To delete all messages including those not associated with an issue, see the **Messages** table below

[^5]: To view all files including those not associated with an issue, see the **Files** table below

[^6]: Including messages associated with an issue or not

[^7]: Whether they're associated with an issue or not

[^8]: From a message search in the Explorer, click the box next to the message then click **Mark Sensitive**.\
    \
    This redacts the email, but doesn't create an issue.

[^9]: Hover over a message header to view a summary

[^10]: A Material delegate is someone who can retrieve a locked message on behalf of another user.\
    \
    The Material delegate must also be a delegate in M365 or Google - that gives them access to the other user's mailbox. In order to unlock a stubbed message, they **also** need to be delegate in Material.\
    \
    Edit delegates in the Explorer/Accounts.

[^11]: multiple tenants

[^12]: one tenant

[^13]: single tenant

[^14]: Audit Logs are located last in the left navigation


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/learn-more/administration/admin-roles/permissions-matrices.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
