> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/learn-more/administration/admin-roles/role-descriptions.md).

# Role Descriptions

## Role Descriptions and Use Cases

{% hint style="warning" %}
Accounts can have multiple roles, however if they're assigned **any** Global roles then all their access will be Global and none restricted to just one tenant.

If accounts have a tenant role and no Global roles, they'll only have permissions on the tenant they're assigned to.

[Learn more here.](/learn-more/administration/admin-roles.md)
{% endhint %}

There are 15 roles available, [described in the tables below](#role-descriptions-and-use-cases).

### Global Roles <a href="#h-email-content-admin" id="h-email-content-admin"></a>

{% hint style="info" %}
Global roles have permissions in all tenants.
{% endhint %}

| Role                                 | Description                                                                                                                                                                                                                                                                                              | Use Case                                                                                                                                                                                    |
| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Super Admin**                      | <ul><li>Full administrative control over the system</li><li>Add tenants and designate other admins</li><li>View the content of messages that are considered suspicious.</li><li><strong>Can't</strong> search for or view the full body of messages without also having the Content Admin role</li></ul> | Typically used by members of an IT or Security team.                                                                                                                                        |
| **Global Analyst**                   | <ul><li>Incident response</li><li>View suspicious message content</li></ul>                                                                                                                                                                                                                              | <p>Typically used by members of an Incident Response or Security team</p><p>These admins can investigate suspicious or potentially malicious emails.</p>                                    |
| **eDiscovery Admin**                 | <ul><li>Force unlock messages</li><li>View and search message content</li><li><strong>Can't</strong> modify system settings</li></ul>                                                                                                                                                                    | Typically used by members of a legal team as part of discovery to unlock mail                                                                                                               |
| **Global Analytics Admin**           | <ul><li>View high-level reports and metrics for any tenant enrolled</li><li><strong>Can't</strong> view fine-grained email data or configure system settings</li></ul>                                                                                                                                   | <p>Typically used by members of a Data Loss Prevention or Data Analysis team.<br><br>These admins periodically review any Material reports and decide if further analysis is necessary.</p> |
| **Global Settings Admin**            | <ul><li>Set up and configure Material across all tenants</li></ul>                                                                                                                                                                                                                                       | <p>Typically used by members of IT to help with the initial configuration of Material.<br><br>These admins can configure settings across all domains.</p>                                   |
| **Global Phishing Simulation Admin** | <ul><li>Ability to create, modify, and delete phishing simulations</li><li>Access reports</li><li>Manage simulation participation and settings</li></ul>                                                                                                                                                 | Global Phishing Simulation Admins can manage all phishing simulations, and create new simulations from scratch across tenants.                                                              |
| **Global Issue Responder**           | Review issue details and apply remediations                                                                                                                                                                                                                                                              | Issue responders have read-only access to the detections and settings that generated the issue and cannot perform message or file searches.                                                 |

### Tenant Roles

{% hint style="info" %}
Tenant roles have permissions in the tenant their account is linked to, but can only be assigned to one tenant. If the user needs these permissions in multiple tenants, assign a [Global role](#h-email-content-admin).
{% endhint %}

| Role                          | Description                                                                                                                                                                                                                                                           | Use Case                                                                                                                                                                                                                                                                                                                                                                                 |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Tenant Admin**              | <ul><li>Full administrative control</li><li>View suspicious message content via Message Search, <strong>however</strong> no access to Email Threat issues. See <strong>Content Admin</strong>.</li><li>Report view access</li><li>Configure tenant settings</li></ul> | This is meant for the person who's responsible for Material's usage within a specific tenant. They have broad privileges so it's typically someone who's organizational role matches that breadth.                                                                                                                                                                                       |
| **Content Admin**             | <ul><li>View, search, and administer message and file content for the tenants their account is linked to.</li><li><strong>Can't</strong> configure system settings.</li></ul>                                                                                         | This role is used by the **few** people with a need to examine **all** content and perform searches. Frequently used by legal, HR, insider threat analysts, or other similar roles.                                                                                                                                                                                                      |
| **Drive Content Admin**       | <ul><li>View, search, and administer file content</li><li><strong>Can't</strong> configure system settings</li></ul>                                                                                                                                                  | Typically granted temporarily, but must be revoked by super admins. Frequently used by an organization's legal team.                                                                                                                                                                                                                                                                     |
| **Email Content Admin**       | <ul><li>View, search, and administer <strong>message</strong></li><li><strong>Can't</strong> configure system settings</li></ul>                                                                                                                                      | Typically granted temporarily and most frequently used by an organization's legal team                                                                                                                                                                                                                                                                                                   |
| **Phishing Simulation Admin** | <ul><li>Create simulations from scratch</li><li>Modify all simulations</li></ul>                                                                                                                                                                                      | <p>Phishing Simulation Admins can manage all phishing simulations, and create new simulations from scratch.</p><p>Note: This role is intended for <a data-footnote-ref href="#user-content-fn-1">dedicated</a> instances. For most instances, assign the <a href="#h-email-content-admin">Global Phishing Simulation Admin role</a> as phishing simulations can span across tenants.</p> |
| **Tenant Enroller**           | <ul><li>Add new tenants to be protected by Material</li><li><strong>Can't</strong> administer or view other tenants</li></ul>                                                                                                                                         | <p>Typically used by an Microsoft 365 Global Administrator or Google Workspace Super Admin account.<br><br>These admins have the ability to authorize Material's connection to the email tenant.</p>                                                                                                                                                                                     |
| **Analytics Admin**           | <ul><li>View high-level reports and metrics for the tenants their account is linked to.</li><li><strong>Can't</strong> view fine-grained email data or configure system settings.</li></ul>                                                                           | <p>Typically used by members of a Data Loss Prevention or Data Analysis team.<br><br>These admins periodically review Material reports on the tenants their account is linked to and decide if further analysis is necessary.</p>                                                                                                                                                        |
| **Settings Admin**            | <ul><li>Set up and configure Material for the tenants their account is linked to</li></ul>                                                                                                                                                                            | <p>Typically used by members of IT to help with the initial configuration of Material.</p><p>These admins can only configure settings of domains their account is enrolled in.</p>                                                                                                                                                                                                       |
| **Issue Responder**           | <ul><li>Review issue details and apply remediations</li></ul>                                                                                                                                                                                                         | Issue responders have read-only access to the detections and settings that generated the issue and cannot perform message or file searches.                                                                                                                                                                                                                                              |

[^1]: single tenant


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/learn-more/administration/admin-roles/role-descriptions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
