User management in BlueCat Horizon comprises roles, groups, and users. Roles provide users and groups with permissions to view objects in the system and perform specific tasks. While the platform comes with built-in roles, you can also create roles to meet your organization's specific requirements.
Before creating users, we recommend creating roles, which comprise permissions. Then you can assign these roles to groups and add users as members to the groups. Users will inherit the roles and permissions assigned to their groups.
Groups can be assigned to multiple roles. If the permissions of the roles conflict, Deny permissions take precedence over Allow permissions. Once you've created groups and users, you can add users to one or more groups. Users inherit permissions from the group(s) they're assigned to based on the roles the group(s) have been assigned to.
Upon installation, the platform creates an Root User account, which can create, modify, deactivate, and delete user accounts, as well as groups and roles.