{"id":60837,"date":"2026-10-02T16:15:37","date_gmt":"2026-10-02T21:15:37","guid":{"rendered":"https:\/\/library-staging.tradingtechnologies.com\/?post_type=doc&#038;p=60837"},"modified":"2026-10-02T16:15:43","modified_gmt":"2026-10-02T21:15:43","slug":"user-management","status":"publish","type":"doc","link":"https:\/\/library-staging.tradingtechnologies.com\/tt-trade-surveillance\/using-tt-trade-surveillance\/user-management\/","title":{"rendered":"User Management"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Score Admins in TT Trade Surveillance hold full access to the product. User Management lets you narrow that access You can build roles from a set of capabilities (the grantable units of access, one or more per page) and assign one role to each Score Admin. The role determines which pages appear for that user and which actions they can take on each one.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">User Management is where a Company Admin builds those roles and assigns them. Open it from the User Management tab in the Trade Surveillance menu bar.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"418\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-1024x418.png\" alt=\"\" class=\"wp-image-60845\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-1024x418.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-300x122.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-768x313.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-1536x627.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-tab-2048x836.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">User Management has three tabs:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Roles<\/strong> \u2014 Lists every role in your company, the capabilities each one grants, and how many users hold it. Create, edit, clone, and delete roles here.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Users<\/strong> \u2014 Lists each user in your company with their assigned role, access level, and resolved capability count. Assign and reassign roles here.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>History<\/strong> \u2014 Displays a read-only record of every role change and every role assignment in your company.\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Access to User Management<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Access to User Management is granted by the <strong>Company Admin<\/strong> permission, which is set in TT User Setup. It is not a capability and cannot be granted by any role in Trade Surveillance \u2014 including <strong>Full-access<\/strong>, or a custom role built with every capability available. This is deliberate: no role you create can be used to give someone the ability to change permissions.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Company Admins<\/strong> \u2014 Can access all three tabs and create, edit, delete, and assign roles within their own company.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>All other users<\/strong> \u2014 Cannot access User Management.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The TT User Setup Company Admin permission is separate from the Score Admin access level. Being a Score Admin does not make you a Company Admin, and a Company Admin can hold any access level.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Access to pages by role<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Pages not granted by your role do not appear in the navigation. If an expected page is missing, your role does not grant it. Contact your Company Admin to request access.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Roles and capabilities<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Roles tab lists every role available in your company.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"421\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-1024x421.png\" alt=\"\" class=\"wp-image-60844\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-1024x421.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-300x123.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-768x316.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-1536x632.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-roles-tab-2048x842.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The table shows:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Role<\/strong> \u2014 The role name, with its description underneath.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Type<\/strong> \u2014 A badge: <strong>System<\/strong> for the two predefined roles, <strong>Custom<\/strong> for any role created in your company.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Grants<\/strong> \u2014 The capability keys the role carries, with a <strong>+n more<\/strong> indicator where the list is truncated.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Assigned<\/strong> \u2014 The number of users currently holding the role.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Row actions appear on the right:&nbsp;<\/p>\n\n\n<?xml encoding=\"utf-8\" ?><figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Icon<\/strong>&nbsp;<\/td><td><strong>Action<\/strong>&nbsp;<\/td><td><strong>Available on<\/strong>&nbsp;<\/td><\/tr><tr><td>Lock&nbsp;<\/td><td>Indicates the role cannot be modified&nbsp;<\/td><td>System roles&nbsp;<\/td><\/tr><tr><td>Copy&nbsp;<\/td><td>Clone the role into a new editable custom role&nbsp;<\/td><td>All roles&nbsp;<\/td><\/tr><tr><td>Pencil&nbsp;<\/td><td>Edit the role&nbsp;<\/td><td>Custom roles only&nbsp;<\/td><\/tr><tr><td>Bin&nbsp;<\/td><td>Delete the role&nbsp;<\/td><td>Custom roles only&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Use <strong>Search roles<\/strong> to filter the list by name.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Role Types<\/strong>&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Predefined (System) roles<\/strong> \u2014 Two roles are available by default with every company and cannot be edited or deleted by any user.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Read-only<\/strong> \u2014 View access to every page. No edit or close rights anywhere.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Full-access<\/strong> \u2014 Every capability available. Note that this does not include User Management, which is permission-gated rather than role-gated, so <strong>Full-access<\/strong> never means &#8220;can administer roles&#8221;.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> Both can be cloned, which is the quickest way to start a role that is close to either one.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Custom roles<\/strong> \u2014 Roles created in your company. A custom role is visible and assignable only within your company, and its name must be unique there.\u00a0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Capabilities<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each page has an access model:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>None \/ Visible:<\/strong> The page is either available or not. Dashboard and DataLens work this way.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>None \/ View \/ Edit:<\/strong>\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>View<\/strong> grants read access; \u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Edit<\/strong> grants the ability to change things. Alerts, Cases, Configurable Models, Company Preferences, Cross-Product Preferences, Reports, and Surveillance work this way.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Surveillance and Cases additionally carry a separate grant for closing, so you can give an analyst the ability to work clusters and cases without the ability to close them.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two rules apply throughout, in the editor and on the server:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Edit includes View.<\/strong> Selecting <strong>Edit<\/strong> for a page automatically grants <strong>View<\/strong>.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Close requires Edit.<\/strong> The close grant is unavailable until <strong>Edit<\/strong> is selected, because you cannot close something you cannot act on.\u00a0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Roles available to users<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Roles apply to Score Admins. The table below lists which users can be assigned roles:&nbsp;<\/p>\n\n\n<?xml encoding=\"utf-8\" ?><figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Access level<\/strong>&nbsp;<\/td><td><strong>Can be assigned a role?<\/strong>&nbsp;<\/td><td><strong>Why<\/strong>&nbsp;<\/td><\/tr><tr><td>Score Admin&nbsp;<\/td><td>Yes&nbsp;<\/td><td>Holds full access by default. These are the users that roles exist to narrow.&nbsp;<\/td><\/tr><tr><td>Score Account Admin&nbsp;<\/td><td>No&nbsp;<\/td><td>Carries a reduced, predefined set of access.&nbsp;<\/td><\/tr><tr><td>Score User&nbsp;<\/td><td>No&nbsp;<\/td><td>Carries a reduced, predefined set of access.&nbsp;<\/td><\/tr><tr><td>Company Admin&nbsp;<\/td><td>No&nbsp;<\/td><td>No Company Admin can change another Company Admin&#8217;s permissions, including their own.&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">On the <strong>Users<\/strong> tab, rows that you cannot assign show a lock icon in place of the pencil. The tab lists every user in your company, but only Score Admin rows are actionable.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To bring a user into the role model (e.g. an auditor) they must first be provisioned as a Score Admin in TT User Setup. Until then their row is locked.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> Reports access carries the reports built on cluster and case data (including the Cluster List Export and Unreviewed Cluster List Export) without a separate Surveillance or Cases capability. Take this into account when you shape a role around either close grant.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Creating a role<\/strong>&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Cloning an existing role<\/strong>&nbsp;<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"545\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-1024x545.png\" alt=\"\" class=\"wp-image-60838\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-1024x545.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-300x160.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-768x409.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-1536x818.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-clone-a-role-2048x1090.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Cloning is usually faster than building a role from scratch and works on any role including the two System roles.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. &nbsp;<\/strong>On the <strong>Roles<\/strong> tab, find the original role that you want to clone.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Click the clone icon on its row.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>Enter a <strong>Role name<\/strong> for the new role.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4.&nbsp; <\/strong>Adjust the access levels as needed, then click <strong>Save role<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The clone is a custom role carrying the original&#8217;s capabilities. The original is unchanged.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Creating a new role<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"547\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-1024x547.png\" alt=\"\" class=\"wp-image-60839\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-1024x547.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-300x160.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-768x410.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-1536x821.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2048x1094.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Roles<\/strong> tab, click <strong>+ Create role<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Enter a <strong>Role name<\/strong>. This is required \u2014 <strong>Save role<\/strong> stays disabled until you provide one.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>Optionally, enter a <strong>Description<\/strong>. This appears under the role name in the <strong>Roles<\/strong> list and can help administrators understand the role&#8217;s purpose.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4.&nbsp; <\/strong>Set an access level for each page.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5.&nbsp; <\/strong>Click <strong>Save role<\/strong>.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"542\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-1024x542.png\" alt=\"\" class=\"wp-image-60840\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-1024x542.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-300x159.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-768x407.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-1536x814.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-2-2048x1085.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The dialog lists the pages:&nbsp;<\/p>\n\n\n<?xml encoding=\"utf-8\" ?><figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Page<\/strong>&nbsp;<\/td><td><strong>Control<\/strong>&nbsp;<\/td><\/tr><tr><td>Alerts&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><\/tr><tr><td>Cases&nbsp;<\/td><td>None \/ View \/ Edit, plus the close grant&nbsp;<\/td><\/tr><tr><td>Configurable Models&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><\/tr><tr><td>Dashboard&nbsp;<\/td><td>None \/ Visible&nbsp;<\/td><\/tr><tr><td>DataLens&nbsp;<\/td><td>None \/ Visible&nbsp;<\/td><\/tr><tr><td>Company Preferences&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><\/tr><tr><td>Cross-Product Preferences&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><\/tr><tr><td>Reports&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><\/tr><tr><td>Surveillance&nbsp;<\/td><td>None \/ View \/ Edit, plus the close grant&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Every page defaults to <strong>None<\/strong>, so a new role starts with no access and you grant access to the role.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> User Management does not appear in the dialog. Access to it is provisioned in TT User Setup through the <strong>Company Admin<\/strong> permission and cannot be granted by a role.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"547\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-1024x547.png\" alt=\"\" class=\"wp-image-60841\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-1024x547.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-300x160.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-768x410.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-1536x820.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-create-a-role-save-role-2048x1093.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Editing a role<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Click the pencil icon on a custom role. The dialog opens with the role&#8217;s current access levels already set; modify the access levels and click <strong>Save role<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> System roles cannot be edited.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Deleting a role<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Click the bin icon on a custom role and confirm. Deletion cannot be undone.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You cannot delete a role while any user is still assigned to it. Reassign those users first. The <strong>Assigned<\/strong> count on the Roles tab indicates how many users are assigned to the role.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"473\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-1024x473.png\" alt=\"\" class=\"wp-image-60842\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-1024x473.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-300x138.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-768x355.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-1536x709.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-delete-a-role-2048x945.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Assigning a role to a user<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Users<\/strong> tab lists every user in your company.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"414\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-1024x414.png\" alt=\"\" class=\"wp-image-60846\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-1024x414.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-300x121.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-768x310.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-1536x621.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assign-a-user-to-a-role-2048x827.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The table shows:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>User<\/strong> \u2014 Name and email address.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Role<\/strong> \u2014 The single role the user holds, or <strong>Unassigned<\/strong>.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Access level<\/strong> \u2014 Score User, Score Account Admin, Score Admin, or Company Admin.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Effective capabilities<\/strong> \u2014 The number of capabilities the user has after their access level has been applied.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Filter the list by access level using the <strong>All \u00b7 Score User \u00b7 Score Account Admin \u00b7 Score Admin \u00b7 Company Admin<\/strong> controls, or search by name or email.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To assign or change a user&#8217;s role:&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Users<\/strong> tab, click the pencil icon on the user&#8217;s row.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Under <strong>Assigned role<\/strong>, select a role. Start typing to filter the list. Each user holds exactly one role.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>The <strong>Effective permissions<\/strong> panel updates to show the capabilities the user will hold.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4.\u00a0 <\/strong>Click <strong>Save<\/strong>.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"544\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-1024x544.png\" alt=\"\" class=\"wp-image-60847\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-1024x544.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-300x159.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-768x408.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-1536x816.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-assigned-role-2048x1088.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The change takes effect immediately and access is recalculated across the platform within 30 seconds. A role change during a departure or an incident is effective right away rather than at the user&#8217;s next login.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Effective permissions<\/strong> shows the users current capabilities. Review this instead of the <strong>Role definition<\/strong> before saving. &nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Users with no role<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A Score Admin who has never been assigned a role has full access. Their assignment dialog shows <strong>No role assigned \u2014 by default this will be full access<\/strong>, although their <strong>Effective capabilities<\/strong> count is shown as 0.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Users you cannot assign a role to<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A lock icon in place of the pencil means you cannot assign that user a role. Filter by access level to see which is which \u2014 every Score Admin row is editable, and every other row is locked. See <a href=\"bookmark:\/\/_Roles_available_to\" target=\"_blank\" rel=\"noreferrer noopener\">Roles available to users<\/a> for more information.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you need to assign a role to a user and their row is locked, they must be provisioned as a Score Admin in TT User Setup first.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Granting an auditor read-only access<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internal auditors, external auditors, and regulators often need access to your surveillance activity without any ability to change it. The <strong>Read-only<\/strong> role provides this.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Before you start:<\/strong> the auditor must be provisioned as a <strong>Score Admin<\/strong> in TT User Setup. Roles can only be assigned to Score Admins, so until that is done their row on the <strong>Users<\/strong> tab is locked.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Users<\/strong> tab, click the pencil icon on the auditor&#8217;s row.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Under <strong>Assigned role<\/strong>, select <strong>Read-only<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3.&nbsp; <\/strong>Click <strong>Save<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Read-only<\/strong> grants view access to every page and no edit or close rights anywhere. It cannot be edited or deleted by any administrator.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pair the role with the <strong>History<\/strong> tab to confirm that the account could not alter anything during the period under review.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Viewing the change history<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>History<\/strong> tab records every role change and every role assignment in your company. It is read-only and append-only. No user can edit or delete an entry, including a Company Admin or a TT Super Admin.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"420\" src=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-1024x420.png\" alt=\"\" class=\"wp-image-60843\" srcset=\"https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-1024x420.png 1024w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-300x123.png 300w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-768x315.png 768w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-1536x629.png 1536w, https:\/\/library-staging.tradingtechnologies.com\/wp-content\/uploads\/2026\/10\/ttts-user-management-history-tab-2048x839.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Each entry records:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>When (UTC)<\/strong> \u2014 The date and time of the change. History timestamps are always UTC, regardless of the time zone set in your preferences.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Actor<\/strong> \u2014 The Company Admin who made the change.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Type<\/strong> \u2014 <strong>Role<\/strong> for a change to a role definition, <strong>User<\/strong> for a change to a user\u2019s assigned roles.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action<\/strong> \u2014 Created, Updated, Assigned, or Deleted.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Detail<\/strong> \u2014 What changed. Role entries name the role and, on creation, the number of capabilities it carries. Assignment entries name the user and the role assigned.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Filter the history using the <strong>All \u00b7 Roles \u00b7 Users<\/strong> controls, search by actor, or set a <strong>From<\/strong> and <strong>To<\/strong> date range.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Capability reference<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nine pages are grantable, carrying 18 capabilities in total. A Full-access role holds all 18, which is what a Score Admin has by default.<\/p>\n\n\n<?xml encoding=\"utf-8\" ?><figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Page<\/strong>&nbsp;<\/td><td><strong>Access model<\/strong>&nbsp;<\/td><td><strong>Capabilities<\/strong>&nbsp;<\/td><td><strong>Notes<\/strong>&nbsp;<\/td><\/tr><tr><td>Dashboard&nbsp;<\/td><td>None \/ Visible&nbsp;<\/td><td>dashboard:view&nbsp;<\/td><td>Trend charts only.&nbsp;<\/td><\/tr><tr><td>Surveillance&nbsp;<\/td><td>None \/ View \/ Edit + close&nbsp;<\/td><td>surveillance:view, surveillance:edit, surveillance:close&nbsp;<\/td><td>Clusters and actions. Edit means act on clusters; close is granted separately.&nbsp;<\/td><\/tr><tr><td>Alerts&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><td>alerts:view, alerts:edit&nbsp;<\/td><td>Edit means create or modify alerts.&nbsp;<\/td><\/tr><tr><td>Reports&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><td>reports:view, reports:edit&nbsp;<\/td><td>Carries the cluster and case reports.&nbsp;<\/td><\/tr><tr><td>Cases&nbsp;<\/td><td>None \/ View \/ Edit + close&nbsp;<\/td><td>cases:view, cases:edit, cases:close&nbsp;<\/td><td>Same shape as Surveillance. Edit means work the case.&nbsp;<\/td><\/tr><tr><td>DataLens&nbsp;<\/td><td>None \/ Visible&nbsp;<\/td><td>datalens:view&nbsp;<\/td><td>Raw transaction data.&nbsp;<\/td><\/tr><tr><td>Company Preferences&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><td>preferences_company:view, preferences_company:edit&nbsp;<\/td><td>Company-wide preferences, including SLAs, tags, and predefined comments.&nbsp;<\/td><\/tr><tr><td>Cross-Product Preferences&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><td>preferences_cross_product:view, preferences_cross_product:edit&nbsp;<\/td><td>Cross-product monitoring configuration.&nbsp;<\/td><\/tr><tr><td>Configurable Models&nbsp;<\/td><td>None \/ View \/ Edit&nbsp;<\/td><td>config_models:view, config_models:edit&nbsp;<\/td><td>Edit means create or modify configurations.&nbsp;<\/td><\/tr><tr><td>User Management&nbsp;<\/td><td>Not grantable&nbsp;<\/td><td>&mdash;&nbsp;<\/td><td>Granted by the Company Admin permission in TT User Setup. No role can grant it.&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Your own user preferences are not gated by any capability and remain available, regardless of what role you hold.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Closing is modelled as a positive grant rather than a restriction. A role that can investigate but not close is one holding surveillance:edit without surveillance:close \u2014 there is no &#8220;cannot close&#8221; rule.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"wp-block-paragraph\">Score Admins in TT Trade Surveillance hold full access to the product. User Management lets you narrow that access You can build roles from a set of capabilities (the grantable units of access, one or more per page) and assign one role to each Score Admin. The role determines which pages appear for that user and which actions they can take on each one.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">User Management is where a Company Admin builds those roles and assigns them. Open it from the User Management tab in the Trade Surveillance menu bar.<\/p>\n<p class=\"wp-block-paragraph\">User Management has three tabs:&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Access to User Management<\/strong>&nbsp;<\/h2>\n<p class=\"wp-block-paragraph\">Access to User Management is granted by the <strong>Company Admin<\/strong> permission, which is set in TT User Setup. It is not a capability and cannot be granted by any role in Trade Surveillance \u2014 including <strong>Full-access<\/strong>, or a custom role built with every capability available. This is deliberate: no role you create can be used to give someone the ability to change permissions.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The TT User Setup Company Admin permission is separate from the Score Admin access level. Being a Score Admin does not make you a Company Admin, and a Company Admin can hold any access level.<\/p>\n<h3 class=\"wp-block-heading\"><strong>Access to pages by role<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Pages not granted by your role do not appear in the navigation. If an expected page is missing, your role does not grant it. Contact your Company Admin to request access.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Roles and capabilities<\/strong>&nbsp;<\/h2>\n<p class=\"wp-block-paragraph\">The Roles tab lists every role available in your company.<\/p>\n<p class=\"wp-block-paragraph\">The table shows:&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Row actions appear on the right:&nbsp;<\/p>\n<p><?xml encoding=\"utf-8\" ?><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Icon<\/strong>&nbsp;<\/td>\n<td><strong>Action<\/strong>&nbsp;<\/td>\n<td><strong>Available on<\/strong>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Lock&nbsp;<\/td>\n<td>Indicates the role cannot be modified&nbsp;<\/td>\n<td>System roles&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Copy&nbsp;<\/td>\n<td>Clone the role into a new editable custom role&nbsp;<\/td>\n<td>All roles&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Pencil&nbsp;<\/td>\n<td>Edit the role&nbsp;<\/td>\n<td>Custom roles only&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Bin&nbsp;<\/td>\n<td>Delete the role&nbsp;<\/td>\n<td>Custom roles only&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Use <strong>Search roles<\/strong> to filter the list by name.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Role Types<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> Both can be cloned, which is the quickest way to start a role that is close to either one.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Capabilities<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Each page has an access model:&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Surveillance and Cases additionally carry a separate grant for closing, so you can give an analyst the ability to work clusters and cases without the ability to close them.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Two rules apply throughout, in the editor and on the server:&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Roles available to users<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Roles apply to Score Admins. The table below lists which users can be assigned roles:&nbsp;<\/p>\n<p><?xml encoding=\"utf-8\" ?><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Access level<\/strong>&nbsp;<\/td>\n<td><strong>Can be assigned a role?<\/strong>&nbsp;<\/td>\n<td><strong>Why<\/strong>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Score Admin&nbsp;<\/td>\n<td>Yes&nbsp;<\/td>\n<td>Holds full access by default. These are the users that roles exist to narrow.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Score Account Admin&nbsp;<\/td>\n<td>No&nbsp;<\/td>\n<td>Carries a reduced, predefined set of access.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Score User&nbsp;<\/td>\n<td>No&nbsp;<\/td>\n<td>Carries a reduced, predefined set of access.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Company Admin&nbsp;<\/td>\n<td>No&nbsp;<\/td>\n<td>No Company Admin can change another Company Admin&#8217;s permissions, including their own.&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">On the <strong>Users<\/strong> tab, rows that you cannot assign show a lock icon in place of the pencil. The tab lists every user in your company, but only Score Admin rows are actionable.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">To bring a user into the role model (e.g. an auditor) they must first be provisioned as a Score Admin in TT User Setup. Until then their row is locked.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> Reports access carries the reports built on cluster and case data (including the Cluster List Export and Unreviewed Cluster List Export) without a separate Surveillance or Cases capability. Take this into account when you shape a role around either close grant.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Creating a role<\/strong>&nbsp;<\/h2>\n<h3 class=\"wp-block-heading\"><strong>Cloning an existing role<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Cloning is usually faster than building a role from scratch and works on any role including the two System roles.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>1. &nbsp;<\/strong>On the <strong>Roles<\/strong> tab, find the original role that you want to clone.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Click the clone icon on its row.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>Enter a <strong>Role name<\/strong> for the new role.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>4.&nbsp; <\/strong>Adjust the access levels as needed, then click <strong>Save role<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">The clone is a custom role carrying the original&#8217;s capabilities. The original is unchanged.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Creating a new role<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Roles<\/strong> tab, click <strong>+ Create role<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Enter a <strong>Role name<\/strong>. This is required \u2014 <strong>Save role<\/strong> stays disabled until you provide one.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>Optionally, enter a <strong>Description<\/strong>. This appears under the role name in the <strong>Roles<\/strong> list and can help administrators understand the role&#8217;s purpose.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>4.&nbsp; <\/strong>Set an access level for each page.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>5.&nbsp; <\/strong>Click <strong>Save role<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">The dialog lists the pages:&nbsp;<\/p>\n<p><?xml encoding=\"utf-8\" ?><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Page<\/strong>&nbsp;<\/td>\n<td><strong>Control<\/strong>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Alerts&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Cases&nbsp;<\/td>\n<td>None \/ View \/ Edit, plus the close grant&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Configurable Models&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Dashboard&nbsp;<\/td>\n<td>None \/ Visible&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>DataLens&nbsp;<\/td>\n<td>None \/ Visible&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Company Preferences&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Cross-Product Preferences&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Reports&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Surveillance&nbsp;<\/td>\n<td>None \/ View \/ Edit, plus the close grant&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Every page defaults to <strong>None<\/strong>, so a new role starts with no access and you grant access to the role.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> User Management does not appear in the dialog. Access to it is provisioned in TT User Setup through the <strong>Company Admin<\/strong> permission and cannot be granted by a role.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Editing a role<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Click the pencil icon on a custom role. The dialog opens with the role&#8217;s current access levels already set; modify the access levels and click <strong>Save role<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> System roles cannot be edited.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Deleting a role<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Click the bin icon on a custom role and confirm. Deletion cannot be undone.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">You cannot delete a role while any user is still assigned to it. Reassign those users first. The <strong>Assigned<\/strong> count on the Roles tab indicates how many users are assigned to the role.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Assigning a role to a user<\/strong>&nbsp;<\/h2>\n<p class=\"wp-block-paragraph\">The <strong>Users<\/strong> tab lists every user in your company.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">The table shows:&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Filter the list by access level using the <strong>All \u00b7 Score User \u00b7 Score Account Admin \u00b7 Score Admin \u00b7 Company Admin<\/strong> controls, or search by name or email.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">To assign or change a user&#8217;s role:&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Users<\/strong> tab, click the pencil icon on the user&#8217;s row.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Under <strong>Assigned role<\/strong>, select a role. Start typing to filter the list. Each user holds exactly one role.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>3. &nbsp;<\/strong>The <strong>Effective permissions<\/strong> panel updates to show the capabilities the user will hold.<\/p>\n<p class=\"wp-block-paragraph\"><strong>4.\u00a0 <\/strong>Click <strong>Save<\/strong>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The change takes effect immediately and access is recalculated across the platform within 30 seconds. A role change during a departure or an incident is effective right away rather than at the user&#8217;s next login.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Effective permissions<\/strong> shows the users current capabilities. Review this instead of the <strong>Role definition<\/strong> before saving. &nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Users with no role<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">A Score Admin who has never been assigned a role has full access. Their assignment dialog shows <strong>No role assigned \u2014 by default this will be full access<\/strong>, although their <strong>Effective capabilities<\/strong> count is shown as 0.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Users you cannot assign a role to<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">A lock icon in place of the pencil means you cannot assign that user a role. Filter by access level to see which is which \u2014 every Score Admin row is editable, and every other row is locked. See <a href=\"bookmark:\/\/_Roles_available_to\" target=\"_blank\" rel=\"noreferrer noopener\">Roles available to users<\/a> for more information.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">If you need to assign a role to a user and their row is locked, they must be provisioned as a Score Admin in TT User Setup first.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\"><strong>Granting an auditor read-only access<\/strong>&nbsp;<\/h3>\n<p class=\"wp-block-paragraph\">Internal auditors, external auditors, and regulators often need access to your surveillance activity without any ability to change it. The <strong>Read-only<\/strong> role provides this.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Before you start:<\/strong> the auditor must be provisioned as a <strong>Score Admin<\/strong> in TT User Setup. Roles can only be assigned to Score Admins, so until that is done their row on the <strong>Users<\/strong> tab is locked.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>1.&nbsp; <\/strong>On the <strong>Users<\/strong> tab, click the pencil icon on the auditor&#8217;s row.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>2.&nbsp; <\/strong>Under <strong>Assigned role<\/strong>, select <strong>Read-only<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>3.&nbsp; <\/strong>Click <strong>Save<\/strong>.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\"><strong>Read-only<\/strong> grants view access to every page and no edit or close rights anywhere. It cannot be edited or deleted by any administrator.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Pair the role with the <strong>History<\/strong> tab to confirm that the account could not alter anything during the period under review.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Viewing the change history<\/strong>&nbsp;<\/h2>\n<p class=\"wp-block-paragraph\">The <strong>History<\/strong> tab records every role change and every role assignment in your company. It is read-only and append-only. No user can edit or delete an entry, including a Company Admin or a TT Super Admin.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Each entry records:&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Filter the history using the <strong>All \u00b7 Roles \u00b7 Users<\/strong> controls, search by actor, or set a <strong>From<\/strong> and <strong>To<\/strong> date range.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Capability reference<\/strong>&nbsp;<\/h2>\n<p class=\"wp-block-paragraph\">Nine pages are grantable, carrying 18 capabilities in total. A Full-access role holds all 18, which is what a Score Admin has by default.<\/p>\n<p><?xml encoding=\"utf-8\" ?><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Page<\/strong>&nbsp;<\/td>\n<td><strong>Access model<\/strong>&nbsp;<\/td>\n<td><strong>Capabilities<\/strong>&nbsp;<\/td>\n<td><strong>Notes<\/strong>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Dashboard&nbsp;<\/td>\n<td>None \/ Visible&nbsp;<\/td>\n<td>dashboard:view&nbsp;<\/td>\n<td>Trend charts only.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Surveillance&nbsp;<\/td>\n<td>None \/ View \/ Edit + close&nbsp;<\/td>\n<td>surveillance:view, surveillance:edit, surveillance:close&nbsp;<\/td>\n<td>Clusters and actions. Edit means act on clusters; close is granted separately.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Alerts&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<td>alerts:view, alerts:edit&nbsp;<\/td>\n<td>Edit means create or modify alerts.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Reports&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<td>reports:view, reports:edit&nbsp;<\/td>\n<td>Carries the cluster and case reports.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Cases&nbsp;<\/td>\n<td>None \/ View \/ Edit + close&nbsp;<\/td>\n<td>cases:view, cases:edit, cases:close&nbsp;<\/td>\n<td>Same shape as Surveillance. Edit means work the case.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>DataLens&nbsp;<\/td>\n<td>None \/ Visible&nbsp;<\/td>\n<td>datalens:view&nbsp;<\/td>\n<td>Raw transaction data.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Company Preferences&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<td>preferences_company:view, preferences_company:edit&nbsp;<\/td>\n<td>Company-wide preferences, including SLAs, tags, and predefined comments.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Cross-Product Preferences&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<td>preferences_cross_product:view, preferences_cross_product:edit&nbsp;<\/td>\n<td>Cross-product monitoring configuration.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Configurable Models&nbsp;<\/td>\n<td>None \/ View \/ Edit&nbsp;<\/td>\n<td>config_models:view, config_models:edit&nbsp;<\/td>\n<td>Edit means create or modify configurations.&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>User Management&nbsp;<\/td>\n<td>Not grantable&nbsp;<\/td>\n<td>&mdash;&nbsp;<\/td>\n<td>Granted by the Company Admin permission in TT User Setup. No role can grant it.&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Your own user preferences are not gated by any capability and remain available, regardless of what role you hold.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">Closing is modelled as a positive grant rather than a restriction. A role that can investigate but not close is one holding surveillance:edit without surveillance:close \u2014 there is no &#8220;cannot close&#8221; rule.&nbsp;<\/p>\n","protected":false},"author":3,"template":"","meta":{"_acf_changed":false,"footnotes":""},"docs-category":[489],"class_list":["post-60837","doc","type-doc","status-publish","hentry","docs-category-using-tt-trade-surveillance"],"acf":[],"_links":{"self":[{"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/doc\/60837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/doc"}],"about":[{"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/types\/doc"}],"author":[{"embeddable":true,"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":2,"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/doc\/60837\/revisions"}],"predecessor-version":[{"id":60849,"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/doc\/60837\/revisions\/60849"}],"wp:attachment":[{"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/media?parent=60837"}],"wp:term":[{"taxonomy":"docs-category","embeddable":true,"href":"https:\/\/library-staging.tradingtechnologies.com\/ja\/wp-json\/wp\/v2\/docs-category?post=60837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}