# Tenancy and Hub Roles

> Overview of role types and their permissions across Tenancies and Hubs.

A typical DekkoSecure deployment comprises a single Tenancy containing a number of Hubs, with each Hub corresponding to a project, team, engagement, or other business process relation.

## General permissions notes

All users can, unless restricted by [Hub policy](https://help.dekkosecure.com/tenancy-management/core-hubs-create-and-manage-hubs#hub-policies) and/or [Tenancy policy](https://help.dekkosecure.com/tenancy-management/tenancy-policies):

- Create Hubs
- Upload files to the root of a Hub
- Upload folders at the root of a Hub
- Create folders at the root of a Hub

See [Hub roles](https://help.dekkosecure.com/tenancy-management/tenancy-and-hub-roles#hub-roles) further down in this article for Hub-level controls such as invite permissions and contact visibility.

## Tenant Manager

Can:

- Access the Tenancy Manager
    - Reset in-Tenancy users’ passwords if the [trusted tenant policy](https://help.dekkosecure.com/tenancy-management/tenancy-policies) is ON (non-SSO/AAD users only).
    - Set Tenancy policies
    - Manage Hubs and Users
    - View traffic and storage activity
    - View Tenancy audit logs (all Hubs in-Tenancy)
    - Set SIEM integrations
    - Delete Hubs
    - Remove users from a Tenancy

Cannot

- Access in-Tenancy user’s content (files and messages) unless they are a member of a Hub and content is shared with them explicitly
- Change Hub-specific settings (manage users, etc.) unless they are a member of the Hub and set as a Hub admin

Tenant admins can be identified by their marking in the Tenancy Manager (*Users* tab):

![](https://help.dekkosecure.com/media/tenancy-management/tenancy-and-hub-roles/Screenshot_2023-04-19_at_2.31.03_pm.png){width=710}

:::tip
The Tenant admin role is assigned by DekkoSecure account management staff. Please contact your account manager to add or remove Tenant admins.
:::

## Hub roles

### Hub admin

Users are automatically set as the Hub admin for each Hub they create. You can find your Hub admin by going to the contact list in the left navigation panel on the dashboard. Hub admins are marked in the contact list with **a star** and **HUB admin** title. Admins are also Hub *Team Member* user type (see below).

Can:

- View Hub contact list
- Manage Hub branding
- Invite users to the Hub (unless disabled by another Hub admin)
- Manage Hub members
    - Set user’s types, set additional Hub admins, remove users
- Access Hub registration links
- View Hub audit logs
- Delete the Hub
- Share files with, request signatures from, and message *Team Member* users in the Hub
- Share files with, request signatures from, and message *External Member* users in the Hub
- Create additional Hubs (if allowed in Tenancy policies)

Cannot:

- Access other in-Hub user’s content (files and messages) unless content is shared with them explicitly

:::tip
Hub admins are specific to each Hub. There is no blanket Hub admin role for all Hubs in a Tenancy.
:::

Hub admins can be identified by their marking in the Tenancy Manager (*Hubs* tab):

![](https://help.dekkosecure.com/media/tenancy-management/tenancy-and-hub-roles/Screenshot_2023-04-19_at_2.52.54_pm.png){width=715}

### Hub member (Team Member)

Can:

- See other *Team Member* users in the Hub contact list
- Share files with, request signatures from, and message other *Team Member* users in the Hub
- Share files with, request signatures from, and message *External Member* users in the Hub
- Invite users to the Hub (if given permission by their inviter)
- Create additional Hubs (if allowed in Tenancy policies)

Cannot:

- Access other in-Hub user’s content (files and messages) unless content is shared with them explicitly
- Access Hub admin controls

### Hub member (External Member)

Can:

- See *Team Member* users in the Hub contact list
- Share files with, request signatures from, and message *Team Member* users in the Hub
- Create additional Hubs (if allowed in Tenancy policies)

Cannot:

- See *External Member* users in the Hub contact list
- Share files with, request signatures from, and message *External Member* users in the Hub
- Invite users to the Hub
- Access other in-Hub user’s content (files and messages) unless content is shared with them explicitly
- Access Hub admin controls

**Note:** The ability to upload files to the root of a Hub can be disabled for users with the *External* member type. This means that when the policy is turned on, *Externals* will only be able to upload files into folders where they have been granted permission, and nowhere else. In addition, *Externals* will not be able to access the sharing menu for files that they upload.

### Member Visibility

This graphic is a simple representation of who can see who (and who can share with who) in a Hub, based on their membership type. If a *Team* member shares a file with two *Externals*, neither external will know that the other has received the file (similar to BCC on email).

![](https://help.dekkosecure.com/media/tenancy-management/core-hubs-invite-users/Screenshot_2024-03-11_at_1.30.23_pm.png)
