Super Admin Role
Super Admin users have complete access to all aspects of Security Cloud Control. Super Admins can do the following:
- Change a user role. 
- Create user records. 
| Note | Though Super Admins can create a Security Cloud Control user record, that user record is not all that is needed for a user to log in to your tenant. The user also needs an account with the identity provider used by your tenant. Unless your enterprise has its own single sign-on identity provider, your identity provider is Cisco Security Cloud Sign On. Users can self-register for their Cisco Security Cloud Sign On account; see Initial Login to Your New Security Cloud Control Tenant for more information. | 
- Create, read, update, and delete any object or policy in Security Cloud Control and configure any setting. 
- Onboard devices. 
- View any page or any setting in Security Cloud Control. 
- Search and filter the contents of any page. 
- Compare device configurations, view the change log, and see VPN mappings. 
- View every warning regarding any setting or object on any page. 
- Generate, refresh, and revoke their own API tokens. If their token is revoked, they can 
- Contact support through our interface and can export a change log.