# Permission Control > Symcon documentation · English · generated on 2026-09-26 > Index: https://www.symcon.de/en/llms.txt Source: https://www.symcon.de/en/service/documentation/module-reference/core-instances/permission-control/ _Requires Symcon >= 8.0_ > **Note:** The authorization control is a paid extension, which can be purchased for every existing Symcon license. For a suitable demo version, please contact our [Support](https://www.symcon.de/en/contact-us/#RBAC%20Extension). The extension can be purchased directly in the [Shop](https://www.symcon.de/en/shop/enterprise/ips-enterprise-rbac). The authorization control makes it possible to create users and roles and assign certain authorizations to them. Users can also be synchronized with an existing LDAP authentication server. ### LDAP configuration (optional) Once all the data for the connection has been entered, the user and role lists can be filled with the equivalents set up with LDAP by clicking on "Synchronize now". If automatic synchronization is activated, users and roles are synchronized at the specified interval. ![Permission control ldap](https://www.symcon.de/media/pages/service/dokumentation/modulreferenz/kern-instanzen/berechtigungssteuerung/22f950346b-1790424938/permission-control-ldap.png) ### Users By default there is the @admin user. This user cannot be edited and has all authorizations. The password for remote access is used to log in with this user. The permissions for accessing a visualization, for example, can be defined in the corresponding [instance](../components/tile-visualization.md). If necessary, a user can be deactivated without deleting them directly. ![Permission control](https://www.symcon.de/media/pages/service/dokumentation/modulreferenz/kern-instanzen/berechtigungssteuerung/4e97724ea8-1790424938/permission-control.png) #### Add user When adding a user, a first name and surname can be entered in addition to the password. These are displayed in the visualization, among other things. When creating, you can choose between the account types "Local account" and "LDAP Sync". If "LDAP Sync" is selected, the UserDN must be entered instead of a password. All desired roles can be selected in the list. ### Roles By default there is the @admin role. This cannot be edited and has all authorizations. Created roles can be added to the created users. The permissions for accessing a visualization, for example, can be defined in the corresponding [instance](../components/tile-visualization.md). ![Permission control](https://www.symcon.de/media/pages/service/dokumentation/modulreferenz/kern-instanzen/berechtigungssteuerung/4e97724ea8-1790424938/permission-control.png) #### Add roles Each role can be given a name when it is created.