
Roles define reusable sets of permissions that can be assigned to multiple users. They allow access to be maintained consistently for users with similar responsibilities, while individual permissions can be added separately through each user’s Permissions subtab.
All roles are available in the main grid, together with their Name, Systemic status, Description and Entra Id. Select Add (+) to create a role or the edit (pencil) icon to open an existing role. The delete (bin) icon is available for non-systemic roles.
The grid supports row selection, column filtering and configuration through the column menus and Columns panel. Refresh reloads the records and Clear Filters removes active filters. Saved layouts are available through Select Grid View, while Data Export provides Excel and CSV exports, including filtered options.

The Info subtab contains the role’s Name and Description, together with the Microsoft Entra Role association and Systemic status. Enter a name and description that identify the role’s purpose. Microsoft Entra Role associates the ATLAS role with a Microsoft Entra role; the corresponding value is displayed as Entra Id in the main grid.
Systemic roles are provided by the system. Their details are displayed as read-only, and their permissions are predefined. Non-systemic roles allow permission sets to be maintained according to the organisation’s requirements.
The Permissions subtab displays the permission set associated with the selected role. For a non-systemic role, select the required permissions and select Save. Users assigned that role receive the associated permissions.
The permission hierarchy follows the same structure as Users → Permissions. Branch arrows expand or collapse individual groups, and the expand icon expands the hierarchy. Search locates permissions, while All, Granted and Changed control which permissions are displayed. Select All provides a bulk selection control, Reset discards unsaved changes and Tree / Grid switches the presentation.
For a systemic role, the message Systemic role - resolved from code rules identifies that the permission set is maintained by the system. Permissions are read-only, but can be reviewed using Search, All, Granted, the hierarchy arrows and the Tree / Grid switch.
Reload refreshes the opened role. For editable roles, Save applies changes and Delete removes the role. The arrow at the top of the right-hand panel collapses or expands the subtab navigation.
Field / Element | Description |
Name | Name identifying the role. Required. |
Description | Description of the role’s purpose. Required. |
Microsoft Entra Role | Association between the ATLAS role and a Microsoft Entra role; displayed as Entra Id in the grid. |
Systemic | Identifies a predefined system role whose details and permissions are read-only. |