> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mezmo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Role-Based Access Control

> Learn how Mezmo roles grant user privileges and how access scopes restrict which log data users can see.

Users are people who have signed up for your Organization. You assign each user one or more [roles](/docs/manage-members) that grant privileges. A role can also carry access scopes that determine which logs the user can see.

## Roles

Roles have default privileges. Mezmo supports four roles:

* **Owner** (`owner`) - Each Mezmo Organization has one owner. The owner can't be restricted, has the most access, and manages both admins and members. The owner can also hold additional roles alongside the Owner role.
* **Admin** (`admin`) - An Organization can have more than one admin. Admins have the second-highest level of access, can view all logs, and can't have their access restricted.
* **Basic** (`basic`) - Standard users of your Organization. (The **Basic** role was formerly named "Member"; this is unrelated to the Users area.) Their log access is governed by the access scopes on the roles they hold.
* **Read-only** (`readonly`) - Read-only members can view logs, run searches, view screens, and export lines. They have no permission to make changes.

A member can hold multiple roles.

Review the [Feature Access Matrix](/docs/feature-access-matrix) for a breakdown of each role's privileges.

## Access Scopes

Access scopes are [Log Analysis](/docs/about-mezmo-log-analysis) query strings attached to a role that limit which logs a user holding that role can see. A role can carry up to 10 access-scope queries. A role with no access scopes grants access to everything.

For example, you can add an access-scope query that matches only logs from Node.js applications and attach it to a role. Users who hold that role see only Node.js logs.

You manage roles and their access scopes at [**Settings > Organization > Roles**](https://app.mezmo.com/manage/roles). You can manage access scopes from the Role form and the Roles list:

* In the Role form, **Permissions** and **Access Scopes** appear on separate tabs.
* A role must grant at least one permission or at least one access scope.
* In the Roles list, an **Access Scopes** badge marks any role that has access scopes.
* Use the **Preview** link to test a query against live tail (the real-time streaming view of incoming logs) before you save.

To learn more about query syntax, see [search log contents](/docs/searching-log-contents).

## Permissions

Beyond the built-in roles, many features grant access through cumulative permission levels that you set on a role's **Permissions** tab. For example, Alerts and the Roles page each have their own levels. This section describes the levels for managing the Roles page.

The Roles page has three cumulative permission levels. **Manage** includes everything in **Write**, and **Write** includes everything in **Read**.

* **Read**: view the Roles page and open a role in view-only mode.
* **Write**: everything Read allows, plus create a role and edit a role.
* **Manage**: everything Write allows, plus delete a role.

If your permission level does not allow an action, its control appears disabled. With only Read, you can open a role, but the form stays view only and you cannot make changes.

You set these levels on the **Permissions** tab when you [create or edit a role](#create-or-edit-a-role).

## Create or Edit a Role

<Note>
  Creating or editing a role requires the **Write** permission level. See [Permissions](#permissions).
</Note>

1. Go to [**Settings > Organization > Roles**](https://app.mezmo.com/manage/roles).
2. Click **Create Role** to add a role, or click **Edit** next to an existing role.
3. Enter a name for the role.
4. On the **Permissions** tab, select the privileges the role grants.
5. On the **Access Scopes** tab, add up to 10 Log Analysis query strings to limit which logs the role can see. Leave this empty to grant access to everything.
6. Click **Save**.

Use **Preview** to test a query against live tail before you save.

## View Users Assigned to a Role

In the Roles list, the **Users** column shows the number of users assigned to each role.

* Click the chevron on a role row to expand it and see the users who hold that role, listed by email address in alphabetical order.
* If you expand a role with no users, it shows the message No users have this role.
* Click a user's email in the expanded list to open the [Users](/docs/manage-members) page filtered to that user.
* Click **Open in users page** to open the [Users](/docs/manage-members) page filtered to that role.
