Only a user with administrator rights can create Access Group Profiles, add roles to profiles, or assign Access Group Profiles to users.
Access Group Profiles are managed in Administration → Master Data → Access Group Profiles. Profiles are assigned to users through Administration → Master Data → Users → Access rights.

Users can add roles to an existing custom Access Group Profile or create a new profile with the required roles.
Important: user cannot add a role directly to a user's Access rights. To give a user an additional role, add the role to an Access Group Profile and assign that profile to the user.
If the required role needs to be added to an existing custom Access Group Profile, an administrator can edit the profile and select the required role.


The Selected Roles Only option controls which roles are displayed in the list.
When Selected Roles Only is enabled, the system displays only the roles that are already selected in the current profile. It does not display all roles available in the system.
If you want to add a new role:
After clearing Selected Roles Only, the list displays the roles available in the system, including roles that are not yet selected in the profile.

Important: If Selected Roles Only is enabled, a role that is not yet included in the profile will not appear in the list. Clear Selected Roles Only before searching for a role that you want to add.
The selected role is now included in the existing custom Access Group Profile.
Note: If the profile is already assigned to users, adding a role to that profile adds the role to the permissions provided by the profile. The affected users must log out and log in again before checking the updated access rights.
If user do not want to modify an existing custom profile, an administrator can create a new Access Group Profile containing the required roles.
The new Access Group Profile now contains the selected roles.

Important: Creating a new Access Group Profile does not automatically assign it to any user.
After creating a new Access Group Profile, an administrator must assign it to the user who needs the roles included in the profile.
The user now receives the roles included in the assigned Access Group Profile.


Note: You do not need to assign the profile again when you add a role to an existing profile that is already assigned to the user. The updated role is included in the permissions provided by that profile.
After adding a role to a profile or assigning a new profile to a user, the affected user must log out and log in again.
Always perform a new login before checking whether the updated access rights are available.
Important: Do not check the updated permissions in the user's existing session. Log out and log in again first.
Standard system Access Group Profiles cannot be modified.
If the required role cannot be added because the profile is a standard system profile, an administrator must create a new custom Access Group Profile containing the required roles instead.
Screenshot: Show a standard system profile where the roles cannot be edited.
Thank you for being FirstBIT Customer!