ActiveRoles Server provides safe, distributed administration through advanced delegation of rights with very high granularity to individual users or groups. However, ActiveRoles Server has a couple of objects that can be managed only by ActiveRoles Server Admin (AR Server Admin).
AR Server Admin is a group for which ActiveRoles Server does not perform permission checking. If the Administration Service itself has sufficient rights to perform a certain task, then AR Server Admin can also perform that task using ActiveRoles Server. By default, AR Server Admin is the Administrators local group on the computer running the Administration Service. You can change this setting when installing the Administration Service. For more information, see ActiveRoles Server Quick Start Guide.
The objects that can be managed only by AR Server Admin are Managed Units and Group Families. Here is the AR Server Admin Only tasks list:
None of these tasks can be delegated. The only task, concerning these kinds of objects that can be delegated, is Change History view.
In ActiveRoles Web Interface, the ability to customize menus, commands, and forms is also given only to AR Server Admin.
If, for some reason, you need to delegate any task from the list above or ability for Web UI customization, it is recommended to add this user as a temporal member to AR Server Admin group.