# Restrict Access to a Test Role Using RBAC

> 📖 If you're new to Test Roles, start with [Create a Test Role](/api-security-testing/how-to/create-a-test-role.md).

You can now **restrict access to test roles** based on user roles (RBAC). This gives you fine-grained control over who can view or use a particular test role.

This is especially useful in collaborative environments where different teams (e.g., Security, QA, DevOps) need access to different sets of tests.

***

## 📘 Prerequisite

Make sure you’ve already created [Custom Roles](/account-management/custom-roles.md) for your team members.

***

## ✅ Steps to Restrict Test Role Access by User Role

1. **Go to Test Roles**
   * Navigate to **API Security Testing → Test Roles**.
2. **Create or Edit a Test Role**
   * You can either create a new Test Role or edit an existing one.
3. **Set Scope Role**
   * In the Test Role configuration form, locate the dropdown labeled **"Scope Role"**.
   * Select one or more user roles from the list.
   * Only users with the selected roles will be able to view or apply this Test Role during testing.
4. **Save**
   * Click **Save** to update the Test Role with the new RBAC restrictions.

***

## 🔒 What Happens After Setting a Scope Role?

* Users without the selected roles will **not see** the Test Role in their list.
* They also won't be able to select the Test Role when triggering a test.
* **Admins and Super Admins** retain visibility over all Test Roles by default.

***

## 🧪 Example Use Case

* **QA Team**: Create a test role named “Regression Suite” and assign it a scope role of **QA**.
* **Security Team**: Set up a test role named “Critical Security Checks” and assign it to the **Security** scope role.

***

## 📎 Related Documentation

* [Create a Test Role](/api-security-testing/how-to/create-a-test-role.md)
* [Custom Roles](/account-management/custom-roles.md)


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.akto.io/api-security-testing/how-to/restrict-test-role-rbac.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
