# Roles and Product Access

> Understand what the User and Manager roles allow, and how your organization's contracts decide which CapaOne features and menus you see.

Source: https://docs.capaone.com/capaone/account-administration/roles-and-product-access/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Two things decide what you can do in CapaOne:

- Your **role** decides whether you can administer users and organizations.
- Your organization's **contracts** decide which features everyone in the organization can use.

## Roles

Each CapaOne user has one role. You set the role when you create or edit a user under
**Users & Organization**.

| Role | What it allows |
|---|---|
| **User** | The default role. Use all the features your organization has, and view and edit your own profile. A user can't change their own role. |
| **Manager** | Everything a user can do, plus **Users & Organization**: create, edit, and remove users and assign their roles; create, rename, and delete sub-organizations; manage the products that sub-organizations can use; set the sign-in methods; and view licenses, billing, and consultant hours. |

If you don't have the Manager role, **Users & Organization** shows that the page requires the
Manager role. Contact your CapaSystems account manager to request access.

Roles don't limit access to features. Every user in an organization sees the same features.

## Product access

The features you see depend on the products your organization has an active contract for. When
you switch organization in the top bar, CapaOne shows the features of that organization.

| Product | What it unlocks |
|---|---|
| **Application Manager** | Windows applications: Repository Apps, Company Apps, and Scripts; application patching; and [Automation](/capaone/application-manager/automation/) workflows. |
| **Mobile Manager** | The Android and Apple sections, and the [Self Service Hub](/capaone/mobile-manager/apple-mdm/self-service-hub/). |
| **Experience Monitor** | [Reliability](/capaone/experience-monitor/reliability/) and the [Event Log](/capaone/experience-monitor/event-log/). The contract also sets how far back reliability data goes. |
| **Security Monitor** | [Security Monitor](/capaone/security-monitor/) and the Security report under [Reporting](/capaone/reference/reporting/). |
| **Provision Manager** | [Provision Manager](/capaone/provision-manager/), driver updates, driver installer configurations, and [Automation](/capaone/application-manager/automation/) workflows for drivers. |
| **Privilege Manager** | [Privilege Manager](/capaone/privilege-manager/) and its configurations. |

The Windows **Dashboard**, **Endpoints**, and **Enrollment** pages are available with any of the
Windows products above. **Windows → Configurations** is available with Privilege Manager or
Provision Manager.

When a feature isn't part of your contracts, CapaOne either hides the menu item or shows a short
introduction to the feature with a way to contact CapaSystems.

To see your organization's products, open your profile. See
[License and Contract Management](/capaone/account-administration/license-and-contract-management/).

## Sub-organizations

A sub-organization can use the products of its parent organization. A Manager in the parent
organization turns each product on or off for the sub-organization under
**Users & Organization → Contracts**. See
[Create organizations and manage users, billing, licenses & contracts](/capaone/account-administration/create-organizations-and-manage-users-billing-licenses-contracts/#contracts).

## Related

- [Accessing account administration inside CapaOne](/capaone/account-administration/accessing-account-administration-inside-capaone/)
- [Manage Sign-in Methods](/capaone/account-administration/manage-sign-in-methods/)
