An Asset Administrator manages all partitions, assets, and accounts:
- Creates (or imports) assets and accounts. 
- Creates partitions and profiles. 
- 
Delegates partition ownership to users. A delegated partition owner has a subset of permissions that an Asset Administrator has. That is, the delegated partition owner is authorized to manage a specific partition and the assets and accounts assigned to that partition. 
- Assigns assets to partitions. 
- 
Manages account password rules. 
- 
Manages ownership for assets, accounts, and partitions. 
NOTE: Asset Administrators can only view the user object history for their own account.
  
    
The Auditor administrator has read-only access to all features, and has the ability to review all access request activity:
- Monitor appliance information 
- Review everything 
- Export object history 
- Run entitlement reports 
There are two additional permission types available once the Auditor role is selected that will help provide limited auditor permissions should you prefer not to use the all-encompassing Auditor role (which incorporates both permission types):
On some pages, it may appear the administrator can edit data, but the change cannot be saved. A message like the following will display: Authorization is required for this request. 
Application Auditor
Application Auditor provides read-only access to features related to the functionality of Safeguard. The Application Auditor permissions correspond with the following roles, however only read-access is allowed:
System Auditor
System Auditor provides read-only access to features related to the operation of Safeguard. The System Auditor permissions correspond with the following roles, however only read-access is allowed:
- 
Appliance 
- 
Operations 
- 
Help Desk 
- 
User 
- 
Global 
 
    
The Authorizer Administrator is the permissions administrator and performs the following:
- Creates (or imports) SPP users. 
- Grants administrator permissions to users. 
- Sets passwords, unlocks, and enables or disables both local and directory user accounts. 
The Authorizer Administrator also has User Administrator and Help Desk Administrator permissions.
IMPORTANT: Authorizer Administrators can change the permissions for their own account, which may affect their ability to grant permissions to other users. When you make changes to your own permissions, they take effect next time you log in.
  
    
A Help Desk Administrator: 
NOTE: Help Desk Administrators can only view the user object history for their own account.