---
title: "FAQ: How do I implement role-based access control?"
canonical: "https://docs.aryaka.com/space/KNOW/1269170384/FAQ%3A%20How%20do%20I%20implement%20role-based%20access%20control%3F"
format: markdown
---
This topic includes questions MyAryaka users often ask about configuring role-based access control, which was released on June 14, 2025. What is role-based access control? The Global Settings > Access Control section allows you to configure users, user groups, and roles for the purpose of controlling access to the features that compose MyAryaka.  In general, the access control process includes the following procedures: Configure users Configure user groups Add users to user groups Import predefined roles or configure custom roles Assign roles to users and user groups Configuration of users and user groups is similar to what you previously experienced in the MyAryaka User Management pages. What happens to my current users? Aryaka Support was responsible for the initial configuration and role assignment of your existing users. The goal is to recreate your existing access permissions within the context of the new user groups, roles, and associated functionality. Migrated users have their access defined by membership in one or more  migration user groups , as described later in the topic.  Prior to the June 14, 2025 release, your users had either Read, Read/Write, or No Access defined as the Access Type in MyAryaka: This Access Type field is still included on the Access Control > User >  userName  page; however, it now only controls access to features that are  not  controlled by role-based access. By default, all users have Read access to Home, Monitor, Status, Alert Dashboard, and non-SLA Report pages. Additionally, by default, all users have Read/Write access to the Quickview Management page. Access to all other MyAryaka pages is determined by role. Additionally, users are configured to either receive or not receive notifications, and whether they can access the Ticketing Portal and the Billing tab. The previous Ticketing Portal and Notifications settings are duplicated on the new User Details page. Billing tab access was previously enforced by assigning one of the two following billing settings for a user:  In MyAryaka—On the user's details page (at Access Control > Users >  userName ), the Billing Tab field is either set to Yes or No. In the management console operated by Aryaka Support—If the Billing Tab field on the user's details page is set to Yes, Aryaka Support further defined the access by making a setting that determined whether the user can see billing fields that display a cost (the amount your organization pays Aryaka for the service).  The new release includes two billing-specific roles—Billing With Amount and Billing Without Amount—that determine the level of access. These roles can be assigned to individual users or to user groups, which then pass the role assignment to all members of the group. What happens to my current user groups? Aryaka Support is responsible for the initial configuration, member assignment, and role assignment of your existing user groups. The goal is to recreate your existing user groups and their members within the context of the new roles and associated functionality. If any of your existing user groups contain partner users and customer users, the migration results in the creation of two user groups: one group of each type (Partner and Customer). Each group type is populated with the matching type of user. The partner user group uses the following naming convention: Mig: <originalUserGroupName> - <CustomerCode>  and is visible in the customer portal. In addition to the migration of your existing user groups—which, after migration, do  not  have roles assigned to them—Aryaka Support creates the following  Mig:  user groups for the purpose of migration. These groups  do  have roles assigned to them and are populated with your users based on their current access type (Read or Read/Write) and billing access. They are detailed in the following table. User Group Role for Migration Notes Admin Admin Customer Group Users who currently have Read/Write access and Billing access are now members of this group. This user group cannot be deleted or renamed. Users can be added and removed from this group. This role cannot be assigned to any other user group. Mig: Read/Write-No Billing Mig: Read/Write Only Customer Group Users who currently have Read/Write access but no Billing access are added to this group. Mig: Read-With Billing Mig: Read-only and Mig: Billing with amount Customer Group Mig: Read-No Billing Mig: Read-only Customer Group Mig: All: Read/Write Admin Partner Group Mig: All: Read-Only Mig: Read-only and Mig: Billing without amount or Mig: Billing with amount Partner Group <originalUserGroupName> No role assigned Customer Group This group retains the current site and service notification configuration. Mig: <originalUserGroupName>  - <CustomerCode> No role assigned Partner Group This group is created with the site and service notification configuration of the original user group. One of the key new features of user groups is that they can be assigned a role, and then that role is passed to all members of the group. Organizations can differ on how they use user groups. For example, one may group together everyone in a geographic location (San Francisco or Building F) for easier user management. Another may group together everyone with a specific job role (Human Resources or Facilities). In the case of location-based group organization, people in the group likely have varied job titles, therefore different role requirements. In the case of job-based group organization, people in the group are more likely to have similar role requirements. Because of this possible issue with user group membership, your user-defined groups are migrated without any roles associated with the user groups. You may find that you want to reorganize your user groups to take advantage of this feature. The Users and User Groups pages link to user and group details pages that contain functionality to assign roles to users and groups: User details page—Contains the Additional Roles tab where you can add roles to the selected user in addition to those obtained from user group membership (if any).  User group details page—Contains the Assign Roles tab where you can add roles to the selected user group. Are there default roles? MyAryaka includes the following roles (note that the roles other than Admin begin with  Mig:  to identify them as the roles created and assigned during migration): Admin—Grants Read/Write access to features that require it. Grants Read access to all other features. Mig: Read/Write—Grants Read/Write access to all features except those on Billing pages. Note that for some features, Write access is not applicable.  Mig: Read-only—Grants Read access to all features except those on Billing pages. Mig: Billing With Amount—Grants Read access to all details on the Billing pages, including those that display a cost. Mig: Billing Without Amount—Grants Read access to details on the Billing pages that do  not  display a cost. By default, users have the highest access available (Read/Write where required, Read otherwise) for all features that are not a part of Config, Billing, and SLA Reports. Why do some users report error messages preventing them from logging in to MyAryaka? If your users encounter the following error message it is likely that their user account does not have any role assigned to it: When role-based access control was introduced, your existing users were placed in migration user groups (groups prefixed by  Mig: ) for the purpose of assigning roles to them. If you have edited the membership of these user groups, created new users and did  not  assign a role to the individual user, or added the user to a user group without a role assigned to it, the user account is considered  unauthorized , resulting in this message at log in. What should I do now that role-based access control is released? We suggest you perform the following tasks as soon as possible to confirm assignments made by the migration process match the access requirements of your organization: Review and edit the roles that are assigned to your users and user groups as required.  Go to the Access Control > Roles >  roleName  page to ensure the users assigned the role that grants Read/Write access to Access Control Management are the people you want to manage the role assignments for individual users and user groups. This access governs critical role mappings. Review the users that are members of the the Admin user group. These users have the highest level of access to all features through the Admin role assigned to the group. Ensure that only appropriate individuals are members of this user group, and remove users if necessary. Use our online help documents for a smooth transition and  learn how to assign roles to users and user groups . Contact Aryaka Support  if you need help mapping your previous permissions to roles. Related topics Role-based access control for customers Manage access control for customers Role-based access control for partners Manage access control for partners