User roles contain rules that define the operations allowed for the user who is assigned the role. Each user role can contain multiple rules and each user can have multiple roles. For example, if role1 allows access only to configuration operations, and role2 allows access only to debug operations, then users who belong to both role1 and role2 can access configuration and debug operations. You can also limit access to specific VLANs, virtual routing and forwarding instances (VRFs), and interfaces. The Cisco NX-OS software provides four default user roles: *network-admin-Complete read-and-write access to the entire NX-OS device (only available in the default VDC) *network-operator-Complete read access to the entire NX-OS device (only available in the default VDC) *vdc-admin-Read-and-write access limited to a VDC *vdc-operator-Read access limited to a VDC Note You cannot change the default user roles. Reference: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx- os/security/configuration/guide/sec_nx-os-cfg/sec_rbac.html#wp1431408