With all the different permissions that can be assigned to a role, it can be difficult to know which permissions you actually need or where to start when creating a new role. It is easy to give a role too many permissions or miss out a required permission that an assigned permission needs in order to work properly.
That is why we have created some predefined Role Templates that you can add when creating a new role (or editing an existing role). These add all the basic permissions that you might need for a certain role (e.g. Email Signature Manager or Contact Manager) and you can still assign additional permissions or remove assigned permissions, as required.
The current Role Templates are:
- Business Unit Manager - Allows the user to create and edit Users and Organizational Units, including the ability to deprovision or delete user profiles.
- Contact Manager - Allows the user to manage contacts, including external contacts, and view user profile aliases. Please note that this role template will only be available to Google domains.
- Apps Integration - Allows the user to copy profiles and external contacts to their personal address book, create appointments in their calendar, and send emails from links within action menus.
- Signature Manager - Allows the user to edit Email Signature Templates and assign them to user emails.
- 1st Line Support - Allows the user to provide 1st line support, including being able to manage and edit users (including passwords, verification and contacts), but they cannot deprovision or delete users. They can also view hidden Users and Organizational Units, when the user last logged in, aliases, suspended profiles and the Organization Unit Hierarchy.
- Security Manager - Allows the user full permissions, with the exceptions of editing Email Signature Templates, Global Settings and Organization Units, managing Smart Teams and their priority level, and viewing their own application logs. The unassigned permissions can easily be assigned, if required.
For additional information on how to apply a role template, please refer to Manage Custom Roles