> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.2/3.-guide-to-navigation/3.3-realm-roles.md).

# 3.3 Realm Roles

#### What Is a Realm Role in Ztrust?

Realm Role is:

* A global role within a realm.
* Useful for cross-client permissions or admin-level roles.
* Can be assigned directly to users or indirectly through composite roles.

<figure><img src="/files/n6QrHz68VD3F5l9cBFvK" alt=""><figcaption><p>Fig 3.3.a: List of avalible realm roles</p></figcaption></figure>

You can use the search box to find a specific role.

Click the Refresh button to see the latest settings.

<figure><img src="/files/WEKKzgSyWTM7ZcydE1T7" alt=""><figcaption><p>Fig 3.3.b: Show number roles per page</p></figcaption></figure>

You can also choose how many roles you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

#### **Role Name**

It includes the list of all the different roles that are already defined in ZTrust.

#### **Composite**

This setting can be either True or False.

When set to True, it means that when this particular role is assigned or unassigned to a user, any associated roles will also be automatically assigned or unassigned to the user.

When set to False, no other roles will be linked with this role.

#### **Description**

It refers to the description for the role which will aid you in identifying its purpose.

This field can be localized by specifying a substitution variable with ${var-name} strings.

<figure><img src="/files/XD1WKgJxTnGg3RcN0uQx" alt=""><figcaption><p>Fig 3.3.c: Option to delete role</p></figcaption></figure>

After clicking on the three dots, you'll find the option to delete the role.

To remove any roles at the realm level, simply click on Delete.

After selecting Delete, a confirmation prompt will appear.

\
Click Delete to remove the role, or click Cancel to keep it.

<figure><img src="/files/lLfe1KKNS4yjLUhFmXGJ" alt=""><figcaption><p>Fig 3.3.d: Conform to delete the role</p></figcaption></figure>

#### **Create Role**

If you want to add a new role, click on Create Role.

After clicking on Create Role, you will be directed to the following screen.

<figure><img src="/files/uD69R45wM7UYIBywZ6OZ" alt=""><figcaption><p>Fig 3.3.e: Role creation page</p></figcaption></figure>

#### **Role Name**

It  indicates the name of the specific role.

#### **Description**

It refers to the description for the role which will aid you in identifying its purpose.

#### **Save**

After entering the Name and Description, if you wish to create the role, click on Save.

#### **Cancel**

If you don’t want to apply those changes, click on Cancel to discard those changes.

After clicking on Save, you will be redirected to the below screen

<figure><img src="/files/GO76DzcveWJWSWKtL50c" alt=""><figcaption><p>Fig 3.3.f: Realm role page</p></figcaption></figure>

Here, the details will be mentioned as given by you during the role creation.

<figure><img src="/files/JM3NcvGOrnR26E7lWzQS" alt=""><figcaption><p>Fig 3.3.g: Role attribute tab</p></figcaption></figure>

Within the Attributes section, you have the ability to define any variable you require for the specific Role.

After clicking on Add attributes, you will be directed to the following screen to add the Key-Value Pair.

Just provide the Key, which is the variable you want to define, and then input its corresponding Value.

Click Add attributes to save the Key-Value pair.

<figure><img src="/files/yPwaHiStCKp3dXQwLpzs" alt=""><figcaption><p>Fig 3.3.h: Role attribute creation</p></figcaption></figure>

To remove a specific Key-Value pair, click on the '-' button.

#### **Save**

Once you've entered the required details, if you want to implement the changes, click on Save.

#### **Revert**

If you don’t want to apply those changes, click on Revert to discard those changes.

<figure><img src="/files/7JnLJwJ2c9L4qFu7zdmZ" alt=""><figcaption><p>Fig 3.3.i: Users in Role section</p></figcaption></figure>

In the Users in Role section, you can view the various users assigned to that specific role.

To add users to this role, click on Users. You will be taken to the Users tab (as shown below), where you can add the necessary users.&#x20;

<figure><img src="/files/ywpYS9sr2x9U6aXo3i0T" alt=""><figcaption><p>Fig 3.3.j: List of users </p></figcaption></figure>

Furthermore, you can assign specific user groups to this role by selecting Groups, which will take you to the Groups tab (as illustrated below), where you can add the role to the groups.

<figure><img src="/files/se5qGY9MyKMcADYTrcAQ" alt=""><figcaption><p>Fig 3.3.k: List available Groups</p></figcaption></figure>

<figure><img src="/files/2z8c4tq8UFb9HW7MTtFy" alt=""><figcaption><p>Fig 3.3.l: Options to add or delete roles in groups</p></figcaption></figure>

In the dropdown menu for Actions, you have the option to either Add associated roles or Delete this role.&#x20;

Selecting Add associated roles will display the following screen.&#x20;

<figure><img src="/files/jDnkvS7qdVoCVrLeFR6D" alt=""><figcaption><p>Fig 3.3.m: List of available roles</p></figcaption></figure>

You can also search for a specific role by using the search box.

Click the Refresh button to see the latest settings.

<figure><img src="/files/7SgQLUVx71OFdn4nDRU1" alt=""><figcaption><p>Fig 3.3.n: Show number roles per page</p></figcaption></figure>

You can also choose how many roles you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

You can then select the checkbox for the specific role you want to associate with this role. Click on the checkbox to select the role, then click on Assign.&#x20;

If you decide not to associate the selected roles, click on Cancel to discard the changes.

<figure><img src="/files/T1HoyAxfpTHScpAY8ecy" alt=""><figcaption><p>Fig 3.3.o: Filter by client roles</p></figcaption></figure>

You also have the option to filter roles based on the clients.

<figure><img src="/files/LMtkFt0BHBw1LZZ1h3bo" alt=""><figcaption><p>Fig 3.3.p: Available role by client</p></figcaption></figure>

You can also search for a specific role by using the search box.

Click the Refresh button to see the latest settings.

<figure><img src="/files/67wtzCMfVzPhogxjhsA8" alt=""><figcaption><p>Fig 3.3.q: Show number roles per page</p></figcaption></figure>

You can also choose how many roles you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

You can then select the checkbox for the specific role you want to associate with this role. Click on the checkbox to select the role, then click on Assign.&#x20;

If you decide not to associate the selected roles, click on Cancel to discard the changes.
