Assign one or more roles. Each role carries its own set of permissions.
Link this user to a client to grant them read-only portal access. Client users cannot access the main system.