# My Invited Users

Any identity or accounts that has been assigned the [**Users**](https://docs.radiusaas.com/settings/permissions#users) role, is able to create [username/password accounts](https://docs.radiusaas.com/admin-portal/users) with [certain constraints](https://docs.radiusaas.com/admin-portal/settings/user-settings).&#x20;

Those accounts are typically used for BYOD or guest access scenarios, enabling a self-sponsored access approach not requiring any administrator interaction. The [Rule Engine](https://docs.radiusaas.com/admin-portal/insights/rule-engine) can be leveraged to segregate such devices from more privileged network segments, e.g. using VLAN tagging.

UPNs that have only been assigned the Users role have access to the **My Invited Users** only and thus have below RADIUSaaS Admin Portal experience:&#x20;

<figure><img src="https://1222554226-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSWU1DQ4UGkqER7uGNUOm%2Fuploads%2FZqnllWpei0r4rxElm3oO%2Fimage.png?alt=media&#x26;token=4683d0e6-f037-41a1-a5d2-d97d472e73c3" alt=""><figcaption></figcaption></figure>
