# Vault Owner Security Profile & Permission Set

The _Vault Owner_ <a href="/en/gr/45887/">standard security profile</a> is included by default in all Vaults. This profile is assigned the _All_ permissions for _Configuration_, _Vault Actions_, _Objects_, and _Tabs_, and is automatically granted any new permissions.

## Included Permission Sets

The _Vault Owner_ standard security profile includes the <a href="/en/gr/22824/#vault-owner-actions">_Vault Owner Actions_</a>, _Business Administrator Actions_, and _System Administrator Actions_ <a href="/en/gr/45887/">standard permission sets</a>.

## Standard Vault Owners Actions & Functionality

Standard _Vault Owners_ are allowed to perform the following actions and functionality not available to other security profiles, regardless of permissions assigned in the permission set:

* Override all document security, except for <a href="/en/gr/2617/">field dependency</a> behavior, including:
  * Create, update, and delete <a href="/en/gr/21330/">document relationship types</a>
  * Delete and edit <a href="/en/gr/5415/">document comments and replies</a>
  * Download document source files


<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: Assigning the <a href="/en/gr/22824/#all-permissions"><em>All Document Actions</em></a> permission to a custom permission set does not grant the same level of override granted to <em>Vault Owners</em>. These users still need the necessary role-based permissions.</p>
    </div>
  </div>
</div>



* Edit all <a href="/en/gr/3200/#system-provided-groups">system provided groups</a> except for the _Vault Owners_ system provided group
* Manage users with the standard _Vault Owners_ security profile:
  * <a href="/en/gr/23647/#assign">Assign users</a> to the standard _Vault Owner_ security profile
  * <a href="/en/gr/23647/#assign">Edit users</a> assigned to the standard _Vault Owner_ security profile
  * <a href="/en/gr/1993/">Grant Veeva Support access</a> as for standard _Vault Owner_
  * <a href="/en/gr/953/#ResettingAUserPassword">Reset passwords</a> for users with a standard _Vault Owner_ security profile
* Assign jobs to <a href="/en/gr/22897/">run as other users</a>
* Cancel <a href="/en/gr/44346/">Vault File Manager</a> upload jobs they created. _Vault Owners_ cannot cancel upload jobs created by other users
* Connect to the  <a class="external-link " href="https://developer.veevavault.com/sdk/#tutorial-using-the-vault-java-sdk-debugger" target="_blank" rel="noopener">Vault Java SDK Debugger<i class="fa fa-external-link" aria-hidden="true"></i></a>
* Perform updates to <a href="/en/gr/46534/#synchronize-legacy-user-and-user-object-records">Legacy User accounts</a>.