# Admin - support roles

<table data-full-width="true"><thead><tr><th width="315">Scope</th><th width="126">S1</th><th>S2 (unrestricted)</th><th>S3 (restricted)</th><th>S4 (read-only)</th><th>S2 (with extras)</th></tr></thead><tbody><tr><td><p><strong>access</strong></p><p>Access to the admin portal.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>access monitoring</strong></p><p>Access to monitoring.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>access raw logs</strong></p><p>Access to confidential scenario data.</p></td><td>-</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>access trackman</strong></p><p>Access to the Trackman Service.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>admins edit</strong></p><p>Access to admin editing.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>apps approve</strong></p><p>Can approve apps.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>apps commit</strong></p><p>Access to commit changes in apps.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>apps edit</strong></p><p>Access to apps editing.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>apps get</strong></p><p>Access to apps.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>apps metadata edit</strong></p><p>Access to apps metadata editing. This permission is child permission of apps edit.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>decrypt</strong></p><p>Decryption of confidential data.</p></td><td>Yes</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>decrypt common</strong></p><p>Decryption of "common data" for packages.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>exceptions get</strong></p><p>Access to the error database.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>-</td></tr><tr><td><p><strong>extras add</strong></p><p>Access to adding extra data and operations.</p></td><td>Yes</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>internal services add</strong></p><p>Can assign internal services.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>log as user</strong></p><p>Possibility to log in as a different user.</p></td><td>Yes</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>organization edit</strong></p><p>Access to organization editing.</p></td><td>Yes</td><td>-</td><td>-</td><td>-</td><td>Yes</td></tr><tr><td><p><strong>organizations get</strong></p><p>Access to the list of all organizations.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>organization view</strong></p><p>Access to organization detail.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>packages edit</strong></p><p>Access to package editing.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>roles edit</strong></p><p>Access to admin organization and team roles editing.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>scenario edit</strong></p><p>Access to scenario editing.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>-</td><td>Yes</td></tr><tr><td><p><strong>scenario logs get</strong></p><p>Access to scenario logs.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>scenarios get</strong></p><p>Access to the list of all scenarios.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>scenario verify</strong></p><p>Scenario verification access.</p></td><td>-</td><td>-</td><td>Yes</td><td>-</td><td>Yes</td></tr><tr><td><p><strong>scenario view</strong></p><p>Access to scenario detail.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>template approve</strong></p><p>Can manage approved templates.</p></td><td>Yes</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>template edit</strong></p><p>Access to template editing</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>templates get</strong></p><p>Access to the list of all templates.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>template view</strong></p><p>Access to template detail.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>users add</strong></p><p>Can add users.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>users edit</strong></p><p>Access to user editing.</p></td><td>-</td><td>-</td><td>-</td><td>-</td><td>-</td></tr><tr><td><p><strong>users get</strong></p><p>Access to the list of all users.</p></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><p><strong>webhook logs get</strong></p><p>Access to the webhook logs.</p></td><td>Yes</td><td>Yes</td><td>-</td><td>-</td><td>Yes</td></tr></tbody></table>
