---
title: Users
slug: manufacturing-connect-edge/users
docTags: 
createdAt: 2024-05-02T13:50:33.400Z
---

The *Users* pane allows you to create and manage user access in Manufacturing Connect Edge.&#x20;

# Relationship of Roles, Groups, and Users

Manufacturing Connect Edge incorporates a Role-based access control (RBAC) to customize user permission settings in the form of three distinct components.

- **Roles**: Each role has a collection of customizable permissions. Roles are added to groups and determine the permissions groups have. See [Role Permissions](docId:8Bdd_MizycbThDCesjhb7) for details.&#x20;
- **Groups**: A group is made up of one or more roles. The roles in a group determine the permissions for the group.&#x20;
- **Users**: Accounts that will be assigned to groups. The one or more groups a user is assigned to determines the roles and permissions the user has.

Working together, a *Role&#x20;*&#x64;etermines the permission settings a *Group&#x20;*&#x77;ill have. A *Group&#x20;*&#x77;ill contain one or more roles that determines its permissions. A *User&#x20;*&#x77;ill be assigned to a *Group&#x20;*&#x77;here it will have access to Manufacturing Connect Edge based on the the Group's one or more *Roles*.

:::hint{type="warning"}
**Important**: The following properties should be kept in mind when adding/editing Roles/Groups/Users.

- A group can receive more than one role (and their respective permission settings) to a resource.
- A user can be assigned to multiple groups.
- If a user is not assigned to at least one group, they will not be able to log in to Manufacturing Connect Edge.&#x20;
- In the case of conflicting permission settings: As long as there is at least one role or group with permissions to a resource, regardless of how many other roles/groups that don't have it, users will receive that resource.
:::

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/5kJHdGV18bL1-3UvqROP6_image.png" size="80" width="804" height="322" caption="Visual representation of roles, groups, and users" position="center" showCaption="true"}

# Default Roles, Groups, and Users

By default, the following user management items are provisioned that can't be deleted.&#x20;

**Roles**

- Administrator
- Viewer

**Groups**

- Administrators
- Viewers

**User**

- admin

The system ensures that at least one user has the appropriate administrative permissions to manage roles, groups, and users.&#x20;

# Default User Permissions

By default, every user has the permission to accept the Manufacturing Connect Edge end-user license (EULA) when logging in the first time. Users can also access their user profile to view their current user permissions and change their password. See [Manage Your User Profile](docId\:c9OGWvHjuHdpsyOhZBeqz) for details.&#x20;

Learn more about [Role Permissions](docId:8Bdd_MizycbThDCesjhb7). &#x20;

# Backup Files and Templates

All role, group, and user configurations are included in backup files. See [Backup/Restore](docId\:gyhE-k9toTAYBo64qBKLB) and [Backup File Contents and File Management](docId:-gxNWa1EmUWhsKU49n8E6) for more information.&#x20;

In template files, only authentication providers are included in template configurations. If you apply a template to a new edge device, you will need to map LDAP groups manually. See [Manage LDAP Providers](docId\:jxjkWJhKdGZ48p3Qf2rYv) for more information.&#x20;

# Legacy User Migration

For Manufacturing Connect Edge instances on version 3.2 and earlier, there were three possible roles: Observer, Developer, and Administrator. When you upgrade to version 3.3 or later:

- Any Administrator role is automatically provisioned to the Administrators group with the group's respective permissions.&#x20;
- Observer and Developer roles are automatically provisioned to the Viewers group with the group's respective permissions.&#x20;

# Access Users UI

:::hint{type="info"}
**Note**: You must have the appropriate permissions to manage roles, groups, and users. By default, the first user (admin user) provisioned in Manufacturing Connect Edge has these user permissions.&#x20;
:::

From the Litmus Edge navigation panel, navigate to **System&#x20;**> **Access Control**.&#x20;
The *Users&#x20;*&#x70;ane appears.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Ut_3EcpIsK6M_IJv5dxMm_image.png)

# Next Steps

- [Add a Role](docId\:CljNCwpqKWRg1PbGdUg_K)&#x20;
- [Manage Roles](docId:3GM47vHAoxrxd578Y5dAL)&#x20;
- [Add a Group](docId\:MTp5BxlMPcO40tFtkTKs5)&#x20;
- [Manage Groups](docId\:C68OLPGWl1QNcNf__s_pD)&#x20;
- [Add a User](docId:5ySYbgEdtk2LWouc79XGK)&#x20;
- [Manage Users](docId\:qNlDL_xf1Ashl3UZvfHBa)&#x20;
- [Manage Your User Profile](docId\:c9OGWvHjuHdpsyOhZBeqz)&#x20;
- [Role Permissions](docId:8Bdd_MizycbThDCesjhb7)&#x20;

