---
title: "Security Basics."
canonical: "https://support.appfire.com/space/DLP/298322307/Security%20Basics."
format: markdown
---
Access to a Box is based on:

- [Global roles](https://appfire.atlassian.net/wiki/spaces/DLP/pages/298287400) defined in App Administration (application access settings - if a user isn't added to the App itself, they won't be able to access any Boxes because they won't even see the App's tab at the top)
- Default roles specified for a Box type
- [Roles](https://appfire.atlassian.net/wiki/spaces/DLP/pages/297994764) configured for an individual Box
- Roles inherited from upper-level Boxes

## Inheritance mode

| **mode** | **description** |
| --- | --- |
| Own with inherited | Box users = manually added + inherited |
| Inherited only | Box users = inherited<br><span style="color: #003366">In the "Inherited only" mode, the Security tab of an individual Box is hidden (you can't access it in Box configuration).</span> |

| <span style="color: #003366">**Change of the inheritance mode affects ALL boxes**</span> |
| --- |
| **from** |  | **to** |  | **result** |
| <span style="color: #003366">**Own with inherited**</span> | → | <span style="color: #003366">**Inherited only**</span> | = | <span style="color: #003366">**manually added users lose access**</span> |
| <span style="color: #003366">**Inherited only**</span> | <span style="color: #003366">**Own with inherited**</span> | <span style="color: #003366">**restores the previously existing users**</span> |

### Inherited security roles

Roles are always inherited from upper levels. 

> ℹ️ **Inherited security roles are not displayed in the Box Security. **
> ℹ️ 
> ℹ️ <span style="color: #003366">To know what user roles have been inherited but aren't being displayed, you have to check</span> the upper levels of the hierarchy (technically, that would include all parent Boxes up to the root level).

**Example**

if Cassandra is a Box editor for "SAFe ART (Smart house App)", she is also automatically a Box editor for "PI 1" and "Iteration 1". In the example below, "Iteration 1" inherits security roles from "PI 1", "SAFe ART (Smart house App)" and "Home" Boxes.

![image2022-10-5_8-0-44.png](media://51914d8f-c6a9-4362-a40d-188d73f136e0)

For example, Angela Hambleton is an Editor in the "Project Portfolio" Box.

![image2022-10-5_8-8-25.png](media://46f803ea-9480-400c-b224-d77f44bc2207)

"Hybrid project (Sport App)" is nested under the "Project Portfolio."

![image2022-10-5_8-10-48.png](media://aa3446ad-4998-4492-807b-a949a8184d17)

In "Hybrid project (Sport App)", Angela Hambleton isn't visible on the user list in Box Configuration, even though user roles are inherited, which makes Angela Hambleton an Editor in the "Hybrid project (Sport App)" Box.

![image2022-10-5_8-12-54.png](media://c4ff178f-f043-43c0-b35b-d48ba7324db2)

## Default security roles assignment

**When you create a box** of a given type, default users and groups are added (per the box type settings).

Existing boxes remain unaffected.