| View the Users' Email Address | Applicable Org Unit Type: Organization   Allows users to: View users' email addresses   Users will see: Email addresses in User Management, Classlist, and Discussions   Also Required: N/A | 
| View Users' Org Defined IDs | Applicable Org Unit Type: Organization   Allows users to: View other users' Org Defined IDs   Users will see: The Org Defined ID field in User Management and Classlist   Also Required: N/A | 
| View User Enrollments | Applicable Org Unit Type: Organization   Allows users to: View users' enrollments   Users will see: The View User Enrollment Log option in the user's context menu in User Management   Also Required: N/A | 
| Create a User in the Database | Applicable Org Unit Type: Organization and Course Offering   Allows users to: Add a new user to the organization   Users will see: When enabled at the organization level, the New User button in User Management When enabled at the Course Offering level, you can add, create, or import users in the course by clicking Add Participants in Classlist   Also Required: N/A | 
| See the User Management tool | Applicable Org Unit Type: Organization   Allows users to: Access the Manage Users tool. Access  the User Attributes Management tool for Manager Dashboard and Learning Groups.    Users will see: The Users link in the  Admin Tools menu. User Attributes in the Admin Tools menu, if Manager Dashboard and Learning Groups is enabled.    Also Required: N/A | 
| View Users' Contact Information | Applicable Org Unit Type: Organization   Allows users to: View contact information   Users will see: Go to This User's > Profile in the context menu of users' names in User Management   Also Required: See the User Management tool | 
| View User Tracking | Applicable Org Unit Type: Organization   Allows users to: Users can view the user login attempts and details on the date, time, and IP address from which users logged in.   Users will see: The  View User Tracking icon in the context menu of users' names in User Management.   Also Required: See the User Management tool | 
| Can End Active Sessions | Applicable Org Unit Type: Organization   Allows users to: Immediately log a user out of all active sessions   Users will see: The End All Active Sessions option in the context menu of users' names in User Management   Also Required: See the User Management tool | 
| Update a User | Applicable Org Unit Type: Organization   Allows users to: Change the information associated with any user in the system   Users will see: The  Edit User Information option in the context menu of users' names in User Management   Also Required:  See the User Management tool | 
| Edit Users' Contact Information | Applicable Org Unit Type: Organization   Allows users to: Modify users' contact information   Users will see: User contact fields on the Edit User page   Also Required: See the User Management tool; Update a User | 
| Edit the Users' Email Address | Applicable Org Unit Type: Organization   Allows users to: Edit email addresses   Users will see: The Email field when editing a user   Also Required: See the User Management tool and Update a User. Also requires that the Email field be added to the CreateUser form in the Form Elements tool. | 
| Send Users a Password Reset Link | Applicable Org Unit Type: Organization   Allows users to: Email a reset link to users   Users will see: The  Email Password Reset option in the context menu of users' names in User Management, or the Email Password Reset Link option in the context menu of users' names in Classlist   Also Required: See the User Management tool (not required to reset a password from the Classlist only); Classlist > Has Access to the Classlist | 
| Unlock Locked User Accounts | Applicable Org Unit Type: Organization   Allows users to: Users can re-activate user accounts that have been locked due to login failures   Users will see: The  Unlock Accounts option in the More actions menu in User Management   Also Required: See the User Management tool | 
| Can Activate or Deactivate Users | Applicable Org Unit Type: Organization   Allows users to: Reset a password for another user   Users will see: The Manually set password check box when editing a user in User Management   Also Required: See the User Management tool; Update a User | 
| Reset the Users' Passwords in the Edit Tool | Applicable Org Unit Type: Organization   Allows users to: Reset a user's password   Users will see: The Reset Password option in User Management, or the Change Account Settings option in the context menu of users' names in Classlist   Also Required: See the User Management tool (not required to reset a password from the Classlist only); Classlist > Has Access to the Classlist | 
| Manage Private User Collections | Applicable Org Unit Type: Organization   Allows users to: Create collections of users with similar properties for bulk enrollments   Users will see: The User Collections tool area header in User Management   Also Required: See the User Management tool; Create a User in the Database | 
| Create Public User Collections | Applicable Org Unit Type: Organization   Allows users to: Create User Collections   Users will see: The New Collection button in User Collections   Also Required: See the User Management tool | 
| Enroll Public User Collections | Applicable Org Unit Type: Organization   Allows users to: Enroll other users in User Collections   Users will see: The Add option in the Users tab of the New/Edit Collection page in User Management   Also Required: See the User Management tool | 
| Edit/Delete Public User Collections | Applicable Org Unit Type: Organization   Allows users to: Edit and delete public user collections   Users will see: The  Edit Properties and  Delete icons in a collection's context menu in User Collections   Also Required: See the User Management tool | 
| Search for Inactive Users | Applicable Org Unit Type: Organization   Allows users to: Search for Inactive Users   Users will see: Inactive Users   Also Required: N/A | 
| Edit Users' Org Defined IDs | Applicable Org Unit Type: Organization   Allows users to: Edit users' org defined IDs   Users will see: Users' org defined IDs   Also Required: N/A | 
| Import Users from this Organization | Applicable Org Unit Type: Organization   Allows users to: If there are multiple organizations on the server, you can import from one org to another   Users will see: The Bulk User Management tool area header   Also Required:  See the User Management tool; Create a User in the Database | 
| Delete a User | Applicable Org Unit Type: Organization   Allows users to: Delete users from the system   Users will see: The Delete User icon in the context menu of the user's name in User Management   Also Required: See the User Management tool | 
| Edit Mail Templates | Applicable Org Unit Type: Organization   Allows users to: Define email templates that are sent out to users in the system (for example, enrolling a user in a course offering)   Users will see: The Mail Template Management link in the  Admin Tools menu   Also Required: N/A | 
| Manage User Exemptions | Applicable Org Unit Type: Course Offering   Allows users to: Instructor role can see the Manage Exemptions page   Users will see: The Manage Exemptions page   Also Required: Has Access to the Classlist (under the Classlist tool) | 
| See User Preferred Locales | Applicable Org Unit Type: Organization   Allows users to: See locales set by the user   Users will see: User preferred locales   Also Required: N/A | 
| Change User Preferred Locales | Applicable Org Unit Type: Organization   Allows users to: Change locales set by users   Users will see: Edit the locale   Also Required:  N/A | 
| Get User Attribute Values (API Only) | Applicable Org Unit Type: N/A    Allows users to: Return all attribute values for a specific user. This applies to the User Attributes API routes (/attributes/users and /attributes/schema)
   Users will see: N/A
   Also Required: N/A
 | 
| Search for '[role]' | Applicable Org Unit Type: Any   Allows users to:  Search for users in the selected role in org units. In discussion posts, tag other users within the same course using @mentions   Users will see: A drop-down list of available roles when searching for users in org units   Also Required: N/A | 
| Impersonate '[role]' | Applicable Org Unit Type: Any   Allows users to: Impersonate users in the selected role   Users will see: The  Impersonate link in the context menu of the users they can impersonate in Classlist and User Management   Also Required: Impersonation requires that the impersonating user has the Impersonate '[role]' permission that matches the organization level role for the user they are impersonating. They may also need the Impersonate '[role]' permission for other roles and org unit types if the user they are impersonating has multiple roles within Brightspace, otherwise the following error message is displayed: "You do not have sufficient permission to impersonate this user; they are enrolled with a higher access level in other areas of the organization." | 
| Enroll '[role]' | Applicable Org Unit Type: Any   Allows users to: Enroll users in the selected role in org units   Users will see: A drop-down list of available roles when enrolling users in org units   Also Required: N/A |