---
title: "Box security roles"
canonical: "https://support.appfire.com/space/DLP/2211582244/Box%20security%20roles"
format: markdown
---
> Macro (aura-html)

## Box security roles

Operations available to a user depend on their security roles.

| **Security role** | **Description** |
| --- | --- |
| - Box Admin | Users or groups with this role have all the permissions granted except for accessing the [App Administration](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212266003) page.<br>Sub-boxes inherit the Box Admin role.<br>A Box Admin can:<br>- administer the Box (access the [box configuration](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212266090) section)
- create sub-boxes (child boxes)
- create a sub-box using a box type with the **Inherited only** mode
- [edit a box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211126467) (name and start and end date)
- [delete a box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212235940)
- [archive a box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211939473)
- [change a box status](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212004764) (not started, in progress, closed)
- [duplicate a box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211189505) configuration and use it to create a new box
- determine who can create, edit, and delete [baselines](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212233564) (other users can still view baselines);
  - Box Admin and Box Editors (default)
  - Box Admins<br>![Baselines security settings on the box configuration page.](media://b7e81f4b-b53b-4ae0-99ec-694af12378cb)<br>- [re-synchronize](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2212004378) the box
- edit the box content (as described in the Box editor role), and change the box configuration settings. |
| Box Editor | Sub-boxes inherit the Box Editor role.<br>A Box Editor can:<br>- [edit the box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211126467) (name and start and end date)
- add, edit, and delete objectives
- add, edit, and delete tasks
- add, edit, and delete dependencies
- switch between the column views
- switch between the risk card views
- manually change the [task structure](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211124630)
- [duplicate box](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211189505) configuration and use it to create a new box
- change the scheduling mode of tasks (including Locked tasks
- modify current column view (they can make temporary changes to what they see on the screen, but they cannot save the new setup and make permanent changes to existing column view configurations) |
| Box Viewer | This role is inherited when you create sub-boxes. Users or groups with this role will not have access to the box configuration. They can view the box content in a read-only way and use the [export](https://appfire.atlassian.net/wiki/spaces/BTdc/pages/3536191698) functionality. |
| Sub-box Creator | The Sub-box Creator role is not inherited. Sub-Box Creator can create Project boxes as sub-boxes under a Portfolio box.<br>Sub-box Creators cannot create a sub-box they cannot delete later.<br>If you grant users a Sub-box Creator role on the Home (root) box level, they will be able to create their own Project boxes but will not be permitted to access or edit other boxes nested under the Home box. |
| Resource Admin | The Resource Admin role is effectively an extended App User role, which means that such a user:<br>- has basic access to the app (can access their user profile and see the App dropdown in the header)
- can access boxes based on individual box security settings - does not receive access to all Boxes automatically like App Admin
- additionally is allowed to administer resource-related global configuration (**Administration** > **Resources** page with all subpages, no access to box types, security)
- cannot access app configuration unless the user is host platform Admin simultaneously. |

## Permissions 

In addition to the Jira permissions and security settings, which the app always respects, you can grant security roles to individual users or to Jira user groups.

> ℹ️ Creating groups requires Jira admin permissions.

The roles can be defined for each Box separately or inherited automatically when you create sub-level Boxes.

## Security and access

> ℹ️ The Box security settings can be configured only when the 'Default Roles' option is selected in the App's configuration. Otherwise, all users will be granted the highest level permissions.

To change the assigned security roles of a given Box, go to **Box Configuration** > **Security**.

**Important: **Only a user with a minimum Box admin security role can access and manage the Box configuration.

> ℹ️ This configuration page will not be visible if the inheritance mode is set to "Inherited only" in the **App's administration** > **Box types** > **Security**.
> ℹ️ 
> ℹ️ The Inheritance mode depends on the box type. When creating a new Box, you must select a type—security settings, including the Inheritance mode and the role template, are copied.

![Screen showing the Box types in the Overview module in the BigPicture](media://1f0124f3-43ed-49d3-adab-e709914de315)

![Screenshot showing security permissions available in BigPicture](media://bfadb9f9-465c-483f-9ef9-533addd893d3)

## Inheritance of roles

Security roles are always [inherited](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211125907) from the upper-level boxes, starting from the Home (root) box. When you create a new box, it will inherit the security roles so that you do not need to assign them from scratch.

When you create sub-boxes, the following roles are inherited:

- Box Admin
- Box Editor
- Box Viewer

The Sub-Box Creator role is not inherited, as it would allow users to create sub-boxes they could not delete. 

> ℹ️ User roles inherited from upper-level boxes are not listed in **Box Configuration** > **Security**. They can be viewed only at the upper level.

## Default box type roles

When you create a new Box, security roles are copied from a Box-type role template. In the settings of each Box type, you can assign roles to users. Then, when you create a new Box, those user roles are copied. Users added based on the template are visible in the **Box Configuration** > **Security section**. 

You can assign default roles in the box type configuration to save time when assigning the security roles.

## Restricting access

App and Jira administrators have access to all existing boxes. Users who have no access to a particular box or are not assigned to any security role will not see the box in the Overview module and the [box switcher](https://appfire.atlassian.net/wiki/spaces/DLP/pages/2211712210) unless a user has access to a sub-box (but not to the upper-level box). The upper-level box will be displayed as a greyed-out row (without links) to show the box structure properly:

![image2022-10-4_15-8-19.png](media://b24e9a73-8e43-4902-9589-cfbbf378fbfe)

## Security roles

Roles can be assigned to individual users or entire Jira user groups.

> ℹ️ The "Access Status" column can display two statuses:
> ℹ️ 
> ℹ️ - **Granted** - informs that a role has been assigned to a user successfully.
> ℹ️ - **No access** - informs that a role has been assigned to a user, but global App permissions are missing. The user doesn't have general access to the App. To grant global permissions to the user, go to **Administration** > **Security** and add the user to AppAdmin or AppUser global permissions.

"Access Status" is shown for added users, not for groups. 

![image](media://85bf221f-cbbf-42f4-adb7-4ac089658abc)

![image](media://24e0686f-e1ce-455f-acfc-1272979e90d2)

![image](media://8753f13b-98c7-4a68-9cec-22ae36298176)