You can create users in OpManager and provide required privileges to them. The option to create users is available only for the admin login account or those accounts which have 'Full Control' privilege. (The account with 'Full Control' privilege here refers to an Administrator user with access to all devices with all the AddOn Modules enabled.)
Administrator User: Administrator Users have unrestricted access to perform read/write operations in OpManager. They add/remove devices, troubleshoot issues, change configurations and more without any limitations i.e., they have complete access.
Operator User: Operator Users have read-only/ restricted access in OpManager. They can be granted further access by the Administrator User.
Custom User: Custom user roles allow administrators to customize user access for different modules in OpManager. The different levels of access that can be provided in OpManager for users through Custom Roles include: Read/Write, Read and No Access. To learn how to create Custom User Roles, click here.
Note: (Applicable only for OpManager EE and OpManager Nexus EE)
From version 126332, users created in the Central server will automatically sync with all probe servers. When creating a user in the Central UI, you can specify the probe servers where the user will have login access. The options are given below,
If a user with the same name already exists on a probe server, the synced username will be suffixed with "_noc", and login access to that specific probe will be disabled.
For more information on creating a user in the Enterprise Edition, click here.
Know more about the various user roles in OpManager.
Scope:
Modules - You can select the add-on modules that you want the user to have access for.
Monitor - Based on the option chosen here, access to devices in the allowed add-on modules will be determined. Click here to learn more about the types of User scopes in OpManager.
Logout and try logging in as the new user and check the privileges.
OpManager (version 129xxx and above) now introduces a Selected Probes scope option for users, along with a redesigned three-step user creation flow for a more streamlined experience.
The user creation wizard is now organized into three clearly defined steps:
This revised flow ensures that probe access is configured before scope is assigned, so the applicable scope options are determined based on the probe selection.

The Probes step allows administrators to control how a user's access is distributed across probe servers in a Central Server setup.
Probe Scope
Grants access to this user across probes in the Central Server.

Enable Probe Login Access
Controls whether the user can log in directly to individual probe web clients. This can be set to All Probes or Selected Probes independently.
The Scope step lets administrators configure which devices and modules the user can access. The available scope options are determined based on the probe selection made in the previous step.
The Scope page is organized by module, including Monitor, NetFlow, NCM, Firewall, OpUtils, DPI, and Applications Manager. Each module can be expanded to review and configure access settings independently.

Monitoring Devices
Under the Monitor section, you can choose the device access level for the user: