> For the complete documentation index, see [llms.txt](https://uidata.gitbook.io/datacentral-knowledge-center/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://uidata.gitbook.io/datacentral-knowledge-center/deployments/tenant-step-by-step/governance-and-security.md).

# Governance and Security

## Creating roles for governance

As the tenant admin, you have the ability to create role schemas that govern specific access to reports or permissions possessed by your users.

To manage these roles in your tenant navigate to Administration section and select 'Roles'.

Role schemas can be categorized into three buckets:

* User group: These roles - Tenant Admin, Report Admin, User Admin, and User - grant users access and permissions to specific areas within the system.&#x20;
* Report group: These roles are attached to reports and users in your tenant. Users can embed reports if they possess the same role attached to the report.
* Row-Level Security group: These roles, used with the Service Principal, ensure that users with specific Row-Level security only access the necessary information from the report.

<figure><img src="/files/30RcNbyPZ8wzP1tvieIk" alt=""><figcaption><p>Create role</p></figcaption></figure>

<figure><img src="/files/pw2enX832J90txE6azp4" alt=""><figcaption><p>Define permissions to role</p></figcaption></figure>

<figure><img src="/files/lGYEmUsnCLnIKtSq3lx1" alt=""><figcaption><p>Overview of roles</p></figcaption></figure>
