# Permission simulator Open **Roles and permissions → Simulator** to see what a role or a specific user can access without impersonating that user or changing the current session. The report covers panel sections, registered module actions, rubric permissions, and recent documents. Every result includes a reason such as a granted or missing permission, an item hidden by system state, administrator access, or the public group `docread` rule. Selecting a user also includes account state and the linked public user group. The simulator is diagnostic only: it does not grant permissions and does not replace permission checks in controllers.