For every role, there is a corresponding system account by the same name that has the role. System accounts cannot be deleted or modified, with the exception of being locked out so they cannot be used to log in.
By default, each new user is granted the monitor role. An administrator can change the role or give a user no role; a user with no role cannot log in to the appliance. If a role is changed while the affected user is logged in, the user will be forcibly logged out. When the user logs in again, the capabilities provided by the new role are available to the user.
Users in all roles can change their passwords and perform other account management functions. For details, see Managing your own account.
For details about the capabilities associated with each role, see Capabilities of local roles on CM Series, EX Series, and NX Series appliances.