A role defines a set of permissions to specific resources.
For example, you can create an Administrator role that has permission to modify resources and create a User role that has permission to view resources. You can assign a role to a group or to individual users.
If a role is assigned to a group, only users in this group and children of this group can see this role in the Role list.
For the illustration of the Role management window, see Figure 1.