<!-- loioe6bdc84a82304bb68ab6cd5b992aac9a -->
# Identity and Access Management for OData Provisioning
Learn about the personas and roles in OData Provisioning, as well as their typical tasks and permissions.
<a name="loioe6bdc84a82304bb68ab6cd5b992aac9a__section_cxz_vsk_pcc"/>
## Personas and Roles
Create a role collection and add the roles described here to that role collection before assigning it to the user who will work with this capability. See [Define a Role Collection](https://help.sap.com/docs/btp/sap-business-technology-platform/define-role-collection).
> ### Note:
> When you subscribe to the OData Provisioning capability, you can assign several associated roles. However, for the SAP Integration Suite, only the following roles should be assigned:*ODPManage*, *ODPAPIAccess*, *APIFullAccess*.
<table>
<tr>
<th valign="top">
Role
</th>
<th valign="top">
Task
</th>
</tr>
<tr>
<td valign="top">
*ODPManage*
</td>
<td valign="top">
- View and register OData services
</td>
</tr>
<tr>
<td valign="top">
*APIFullAccess*
</td>
<td valign="top">
- Get runtime access to the registered OData services.
</td>
</tr>
<tr>
<td valign="top">
*ODPAPIAccess*
</td>
<td valign="top">
- Access the service document.
</td>
</tr>
</table>
**Related Information**
[OData Provisioning](../odata-provisioning-d257fc3.md "OData Provisioning, a capability of SAP Integration Suite, exposes business data and business logic as OData services on SAP Business Technology Platform, enabling you to run user-centric applications.")