
In a Global Account, you can create platform users and assign predefined role collections to them.
To create a user, you need to navigate to Security → Users, and choose the Create button in the top-right corner.
When creating a new user, you always have to specify the identity provider. By default, users are created using the default identity provider SAP ID service. If you've configured a custom identity provider in a global account, you can change the IdP in the Identity Provider field.

There's one predefined role collection for administrative tasks and one for read-only access to the global account.
With the Global Account Administrator role collection, the user can perform the following tasks:
- Create new and edit existing Subaccounts, within the Global Account
- Manage entitlements
- Manage users
- Manage role collections
With the Global Account Viewer role, the user only gets read access to the mentioned items.
With the authorizations from predefined roles for Global Accounts, the user is not permitted to access any Subaccount that has been not created by them.