---
title: "Can't add new Security Policy Roles\\Change Owner and Roles Manager"
slug: "cannot-add-new-security-policy-roles-change-owner-and-roles-manager"
updated: 2025-09-02T14:10:04Z
published: 2025-09-02T14:10:04Z
canonical: "support.controlup.com/cannot-add-new-security-policy-roles-change-owner-and-roles-manager"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.controlup.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Can't add new Security Policy Roles\Change Owner and Roles Manager

## Problem
The Organization Owner and the Roles Manager fields are greyed out and can't be changed.  
![Organization Owner and the Roles Manager fields greyed out](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406501453329GreyedOut.png)

The Security Policy actions are also greyed out and can not be changed.  
![Security Policy actions greyed out](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406501497745NoPermissionsToChange.png)

## Root Cause
Your user logged in to the Real-Time DX Console is **not** the Owner or the Roles Manager.


## Solution
The first user that has logged in to the ControlUp organization automatically becomes the Organization Owner and Roles Manager. If the owner and/or Role Manager is set to a specific user account, then only this Active Directory (AD) user can make changes in the Security Settings.  

It is best practice to set an AD group as the owner and Roles Manager and not a specific AD user account. In this case, any user that belongs to the AD group acts as an Organization Owner and Roles Manager.  

To solve the specific problem,

 1. Run the Console with the local AD account of the owner/Roles Manager. Press Shift, right-click the **ControlUpConsole.exe**, and select **Run as different user**.
![Run as different user selected](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406505996177SelectDifferentUser.png)
 2. In the Console, click the **Security Policy** pane.
3. Click the **Manage Roles** button. The Security Settings window appears.  
![Manage Roles button](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406506138257ManageRoles.png)
 4. Click the **...**	  button and select the AD group that you want to assign the Owner and Roles Manager.  
![Owner and Roles Manager fields](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406506061841ChangeUser.png)
 5. In the Account Browse window, click the **Search** button and select the AD user group. Click **OK**  to confirm your selection.  
 
The selected AD group is now set as the new Organization Owner. Click **OK** to save the changes.
![AD group set as the new Organization Owner](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/4406511017105ApplyChanges.png)

From now on, all users in this group act as Organization Owners.
