Direct grants
Direct grants assign a single capability selectively, without creating a dedicated role for it. They are meant for one-off exceptions; for permanent responsibilities, roles are the right way.

Use Grant to assign a capability. The dialog asks for two values:
- Role name – the role the capability applies to
- Capability – the capability to grant, for example
access:admin(access the admin area) ormanage:roles(manage roles)

Every granted and revoked capability is recorded in the audit log. Who currently holds administration access is shown by the Admin sources tab under Users and groups.