# Striim 3.10.1 documentation

#### Roles

Roles associate permissions with users and namespaces. A role may contain multiple permissions and multiple roles.

The default system-level roles that exist in a new Striim installation are:

role

A user with this role:

is a superuser, that is, may perform any action, including managing users, roles, applications, and clusters. By default, only users with this role have access to the admin namespace.

Global.agentrole

is assigned to the internal sys user for use in authenticating Forwarding Agents when they connect to the cluster

is automatically granted the admin role for every namespace created.

Global.appdev

is automatically granted the dev role for every namespace created.

Global.appuser

is automatically granted the enduser role for every namespace created.

Global.serverrole

is assigned to the internal sys user for use in authenticating servers when they connect to the cluster

Global.systemuser

This role is automatically granted to new users. By default, it allows use of types, property templates, and deployment groups in the Global namespace.

Global.uiuser

This role is automatically granted to new users. By default, it allows access to the Apps, Dashboard, Flow Designer, Monitor, and Source Preview pages.

The following roles are automatically created for each namespace:

role

A user with this role:

can perform any action within the namespace.

<namespace>.dev

can perform any action within the namespace except DROP, GRANT, and REVOKE.

<namespace>.enduser